Gentoo Archives: gentoo-announce

From: glsamaker@g.o
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202212-05 ] Mozilla Network Security Service (NSS): Multiple Vulnerabilities
Date: Mon, 19 Dec 2022 02:08:50
Message-Id: 167141532237.8.3747410710459650532@2ac734cbf5a7
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202212-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: Mozilla Network Security Service (NSS): Multiple Vulnerabilities
9 Date: December 19, 2022
10 Bugs: #827946, #836386, #848984, #877169
11 ID: 202212-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been discovered in NSS, the worst of which
19 could result in arbitrary code execution.
20
21 Background
22 ==========
23
24 The Mozilla Network Security Service is a library implementing security
25 features like SSL v.2/v.3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12,
26 S/MIME and X.509 certificates.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 dev-libs/nss < 3.79.2 >= 3.79.2
35
36 Description
37 ===========
38
39 Multiple vulnerabilities have been discovered in Mozilla Network
40 Security Service (NSS). Please review the CVE identifiers referenced
41 below for details.
42
43 Impact
44 ======
45
46 Please review the referenced CVE identifiers for details.
47
48 Workaround
49 ==========
50
51 There is no known workaround at this time.
52
53 Resolution
54 ==========
55
56 All Mozilla Network Security Service (NSS) users should upgrade to the
57 latest version:
58
59 # emerge --sync
60 # emerge --ask --oneshot --verbose ">=dev-libs/nss-3.79.2"
61
62 References
63 ==========
64
65 [ 1 ] CVE-2021-43527
66 https://nvd.nist.gov/vuln/detail/CVE-2021-43527
67 [ 2 ] CVE-2022-1097
68 https://nvd.nist.gov/vuln/detail/CVE-2022-1097
69 [ 3 ] CVE-2022-3479
70 https://nvd.nist.gov/vuln/detail/CVE-2022-3479
71 [ 4 ] MFSA-2021-51
72
73 Availability
74 ============
75
76 This GLSA and any updates to it are available for viewing at
77 the Gentoo Security Website:
78
79 https://security.gentoo.org/glsa/202212-05
80
81 Concerns?
82 =========
83
84 Security is a primary focus of Gentoo Linux and ensuring the
85 confidentiality and security of our users' machines is of utmost
86 importance to us. Any security concerns should be addressed to
87 security@g.o or alternatively, you may file a bug at
88 https://bugs.gentoo.org.
89
90 License
91 =======
92
93 Copyright 2022 Gentoo Foundation, Inc; referenced text
94 belongs to its owner(s).
95
96 The contents of this document are licensed under the
97 Creative Commons - Attribution / Share Alike license.
98
99 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature