Change logs for nss source package in Artful

  • nss (2:3.32-1ubuntu3) artful; urgency=medium
    
      * SECURITY UPDATE: Use-after-free in TLS 1.2 generating handshake hashes
        - debian/patches/CVE-2017-7805.patch: Simplify handling of
          CertificateVerify in nss/lib/ssl/ssl3con.c, nss/lib/ssl/ssl3prot.h.
        - CVE-2017-7805
    
     -- Marc Deslauriers <email address hidden>  Fri, 29 Sep 2017 12:17:39 -0400
  • nss (2:3.32-1ubuntu2) artful; urgency=medium
    
      * Initialise curve variable in a test file, resolves FTBFS.
    
     -- Dimitri John Ledkov <email address hidden>  Thu, 24 Aug 2017 07:21:27 -0400
  • nss (2:3.32-1ubuntu1) artful; urgency=medium
    
      * Merge with Debian; remaining changes:
        - When building with -O3, build with -Wno-error=maybe-uninitialized.
    
    nss (2:3.32-1) unstable; urgency=medium
    
      * New upstream release.
    
    nss (2:3.31-1) unstable; urgency=medium
    
      * New upstream release.
      * debian/libnss3.symbols: Add NSS_3_31 and NSSUTIL_3.31 symbol versions.
    
    nss (2:3.30.2-1) experimental; urgency=medium
    
      * New upstream release.
    
    nss (2:3.30.1-1) experimental; urgency=medium
    
      * New upstream release.
    
    nss (2:3.30-1) experimental; urgency=medium
    
      * New upstream release.
      * debian/libnss3.symbols: Add NSS_3.30 and NSS_3.30.0.1 symbol versions.
    
    nss (2:3.29.1-1) experimental; urgency=medium
    
      * New upstream release.
    
    nss (2:3.29-1) experimental; urgency=medium
    
      * New upstream release.
      * debian/libnss3.symbols: Add NSSUTIL_3.25 symbol version.
    
    nss (2:3.28.1-1) experimental; urgency=medium
    
      * New upstream release.
      * debian/libnss3.symbols: Add NSS_3.28 symbol version.
    
    nss (2:3.27.1-1) experimental; urgency=medium
    
      * New upstream release.
      * debian/libnss3.symbols: Add NSS_3.27 symbol version.
    
     -- Marc Deslauriers <email address hidden>  Wed, 23 Aug 2017 13:09:20 -0400
  • nss (2:3.28.4-0ubuntu2) artful; urgency=medium
    
      * SECURITY UPDATE: DoS via empty SSLv2 messages
        - debian/patches/CVE-2017-7502.patch: reject broken v2 records in
          nss/lib/ssl/ssl3gthr.c, nss/lib/ssl/ssldef.c, nss/lib/ssl/sslimpl.h,
          added tests to nss/gtests/ssl_gtest/ssl_gather_unittest.cc,
          nss/gtests/ssl_gtest/ssl_gtest.gyp, nss/gtests/ssl_gtest/manifest.mn,
          nss/gtests/ssl_gtest/ssl_v2_client_hello_unittest.cc.
        - CVE-2017-7502
    
     -- Marc Deslauriers <email address hidden>  Fri, 16 Jun 2017 08:12:38 -0400
  • nss (2:3.28.4-0ubuntu1) artful; urgency=medium
    
      * Updated to upstream 3.28.4 to fix security issues and get a new CA
        certificate bundle.
      * SECURITY UPDATE: DES and Triple DES ciphers birthday attack
        - CVE-2016-2183
      * SECURITY UPDATE: out-of-bounds write in Base64 decoding
        - CVE-2017-5461
      * debian/patches/*.patch: refreshed for new version.
      * debian/control: bump libnspr4-dev to 4.13.1.
      * debian/libnss3.symbols: added new symbols.
    
     -- Marc Deslauriers <email address hidden>  Thu, 27 Apr 2017 13:13:44 -0400
  • nss (2:3.26.2-1ubuntu1) zesty; urgency=medium
    
      * Merge with Debian; remaining changes:
        - When building with -O3, build with -Wno-error=maybe-uninitialized.
    
    nss (2:3.26.2-1) unstable; urgency=medium
    
      * New upstream release.
    
    nss (2:3.26-2) unstable; urgency=medium
    
      * debian/libnss3.symbols: SSL_GetCipherSuiteInfo and SSL_GetChannelInfo need
        newer versions despite the symbol versions.
    
     -- Marc Deslauriers <email address hidden>  Fri, 02 Dec 2016 08:48:03 -0500