-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 13 Jul 2019 20:38:31 -0400 Source: nss Binary: libnss3 libnss3-1d libnss3-tools libnss3-dev libnss3-dbg Architecture: source amd64 Version: 2:3.26-1+debu8u5 Distribution: jessie-security Urgency: high Maintainer: Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org> Changed-By: Roberto C. Sanchez <roberto@debian.org> Description: libnss3 - Network Security Service libraries libnss3-1d - Network Security Service libraries - transitional package libnss3-dbg - Debugging symbols for the Network Security Service libraries libnss3-dev - Development files for the Network Security Service libraries libnss3-tools - Network Security Service tools Changes: nss (2:3.26-1+debu8u5) jessie-security; urgency=high . * Non-maintainer upload by the LTS Team. * Repackage the new upstream release as debian/patches/nss-3.26.2.patch on top of nss-3.26 to avoid having a version higher than in jessie. * CVE-2019-11719: Out-of-bounds read when importing curve25519 private key * CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a segmentation fault Checksums-Sha1: 50f015b2d99c9be0772d205869c934c88bd544f0 2252 nss_3.26-1+debu8u5.dsc dfc2c405e3055e3cd902908436c592eb0fbed1ba 41124 nss_3.26-1+debu8u5.debian.tar.xz 3f36a28a2cd34d9145c3779e22862ab68e6060e2 1161070 libnss3_3.26-1+debu8u5_amd64.deb c96c1a8b1b2db4152a2ae6bb8ce6656d1fdf2ac9 18784 libnss3-1d_3.26-1+debu8u5_amd64.deb 9a47fbe07194d9afdde28cc7489cab6f81d4c535 784980 libnss3-tools_3.26-1+debu8u5_amd64.deb 441fb69a55a80c5d0c95741b0193bd0a4d612522 233562 libnss3-dev_3.26-1+debu8u5_amd64.deb 875c1e47c6035b796bd0283b6bb5691af1e509e9 8199800 libnss3-dbg_3.26-1+debu8u5_amd64.deb Checksums-Sha256: 2b395f00aedbe5193cd6173856867fa6b58c3c25d0e98448b9ccbbda27f6e9f4 2252 nss_3.26-1+debu8u5.dsc 861eb9d3f9a2f308ba9acaee77ac976faba1d3449fa756ff9f5ee6e107958300 41124 nss_3.26-1+debu8u5.debian.tar.xz fa492fc35a8096dc4341d62a9d97ffc2d4e6d87821ff13f13b7e792175b5482b 1161070 libnss3_3.26-1+debu8u5_amd64.deb 0d119014db57bd7625daf417999f446f405ee9aa5af63452bdfda1a5981151f1 18784 libnss3-1d_3.26-1+debu8u5_amd64.deb 1f933ff2c66fa5d101b17f3301bcc717e1666a1283c3fb0318a86d4b8f3783e4 784980 libnss3-tools_3.26-1+debu8u5_amd64.deb 2356e02a41bfd3b79d4106106d29177d836efd0f4fa8abc928e72f66233b0b5d 233562 libnss3-dev_3.26-1+debu8u5_amd64.deb 3e9b38a2dcbfc0471ba225cea95a9a6ac64d87091c2e6ee21b4a70554502b4d3 8199800 libnss3-dbg_3.26-1+debu8u5_amd64.deb Files: 0b2ca637946d25795164d1b0e6d89336 2252 libs optional nss_3.26-1+debu8u5.dsc f619cd04c6317ddc2d80c22a01e228d3 41124 libs optional nss_3.26-1+debu8u5.debian.tar.xz 9bf8a4bd87d9e8c8a518d52eb14c53f7 1161070 libs optional libnss3_3.26-1+debu8u5_amd64.deb 4733ad5c080b730e5601cc27e3bbfa69 18784 oldlibs extra libnss3-1d_3.26-1+debu8u5_amd64.deb 678c1f47011ccf2a1992fe840bc67948 784980 admin optional libnss3-tools_3.26-1+debu8u5_amd64.deb 4edf939f2766fe07a85756259c4c3c3b 233562 libdevel optional libnss3-dev_3.26-1+debu8u5_amd64.deb 47a941b643ee9910c95fc77ce476b7e2 8199800 debug extra libnss3-dbg_3.26-1+debu8u5_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEz9ERzDttUsU/BH8iLNd4Xt2nsg8FAl0yWSoACgkQLNd4Xt2n sg963A//aeFDuOJI4/i3obFEqbDABxgRHKhVG/MHiuN6tnQ5wzrAEqg1GO+/z1a2 vymkFsDtS6swg16kaPBEWAGLjx4suQO+y1RrHgvt2s32ZNH0lWMRug9TSYArjdJa yIkuceAmaGL+PhJ2MIbcH2ICp7fcHPOHwJUNA+Jv41iYTN/o4fi7Ndl9Hy7d+4pl yuICiHB/i+GpNSnMXkpvSXEn4W6KfFizf0OsG/7xmtbQ5l00bWz+BNJtNpQr+C4q OiOVzdgqWuV/aVKsg4fsZOI6BUosudy34hzvqEpXqk6UG0JM7rO+2A2mqz2rhkmj F1Y195Xtt5aBJXfQiI1i7aPxpZL+06Mc5B5QIk7Y0mWO/CDoCJTZZYdIE8UIvcui 7n3LXM2YfkeSK8FEbsNLR6UvvKLsi9lWKEwCmnbNYZTTv1WXlAlKRf9glTisZLHh +AIYVA5boXGB/nzhnISuZnb4nw3q9noz81Vh4wY0F7WQfciexfk6CzqFGBtRcb1t ShDhb/2Z2tOT3BKIIXX89GGuz9XPfS4R8lwFAKOCiT+VF3+4950vsygxkrTT6K9R Il89HhCON104UdUfzzU7Y3vF2qBu+O5Lif7AfzCXlMHf1KNSYsKLywGxXi5VJk8J 2cgvjmv3hEt8y9/WYQ3pAN9DRzBpabPapF52QKd3Wd4r23VCQUM= =lxxO -----END PGP SIGNATURE-----