-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 06 Jan 2020 22:25:29 +0100 Source: nss Binary: libnss3 libnss3-1d libnss3-tools libnss3-dev libnss3-dbg Architecture: source amd64 Version: 2:3.26-1+debu8u10 Distribution: jessie-security Urgency: high Maintainer: Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libnss3 - Network Security Service libraries libnss3-1d - Network Security Service libraries - transitional package libnss3-dbg - Debugging symbols for the Network Security Service libraries libnss3-dev - Development files for the Network Security Service libraries libnss3-tools - Network Security Service tools Changes: nss (2:3.26-1+debu8u10) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2019-17006: It was found that certain cryptographic primitives in nss did not check the length of the input text. This could result in a potential heap-based buffer overflow. Checksums-Sha1: f5f7db1907dd28d9621cabdeeb38e42d8b067d74 2407 nss_3.26-1+debu8u10.dsc cec14d7a49fbe347dc73d8c37511622407754e75 44532 nss_3.26-1+debu8u10.debian.tar.xz f34dc204ee54075431232d523ffe4e16888e5440 1174614 libnss3_3.26-1+debu8u10_amd64.deb 9adcc86312a2ab1c051c08c73f44cb9af0f64565 19160 libnss3-1d_3.26-1+debu8u10_amd64.deb bc21870824f076e1e12dcfb6e790afc28ec06bcc 785230 libnss3-tools_3.26-1+debu8u10_amd64.deb e822ea9fab620910b7c53f5ca5917eb876dbe9e2 241930 libnss3-dev_3.26-1+debu8u10_amd64.deb c7ed449dc016fb1b6813f2990b1c8f358deb0578 8198842 libnss3-dbg_3.26-1+debu8u10_amd64.deb Checksums-Sha256: 976720de01e3f710b99116424d325c117f91f0c5bc1a7773f71893de705363a6 2407 nss_3.26-1+debu8u10.dsc 184920f181118ef397e4670a2c5324a9281ec2fe12449d2fc45423de457a996d 44532 nss_3.26-1+debu8u10.debian.tar.xz 6a3e4df1d3efaaf087e8399bc7c45c75bb98ce43ebf083b1819518ea4087f55a 1174614 libnss3_3.26-1+debu8u10_amd64.deb 59823a674ecabcea3d002c25b30a56006f337a36998928202c7ee507be076a9e 19160 libnss3-1d_3.26-1+debu8u10_amd64.deb aa7ca366538fb9e7cbf8596ae18aaaada64182e0b1c8925b81b28cd40b22f215 785230 libnss3-tools_3.26-1+debu8u10_amd64.deb ec8af40d3b692dbb73553673844f75dbfc49ae10351039d3477db99ba1f1149b 241930 libnss3-dev_3.26-1+debu8u10_amd64.deb e5118472aaa17cd26e92d073834cdb4e919c68d8cbd6cd551374f08056335d5d 8198842 libnss3-dbg_3.26-1+debu8u10_amd64.deb Files: 8c4de8ecdda21c362929b49e93ceb7cc 2407 libs optional nss_3.26-1+debu8u10.dsc f69037fd2509f8f1f8beefee34cf750c 44532 libs optional nss_3.26-1+debu8u10.debian.tar.xz 90c6c8689c4d7c0f7a53afbaf243bce5 1174614 libs optional libnss3_3.26-1+debu8u10_amd64.deb 5a00b441760e1dd63a1c796fcb408855 19160 oldlibs extra libnss3-1d_3.26-1+debu8u10_amd64.deb 8933966fe03c515997d1d6a5b9675fc9 785230 admin optional libnss3-tools_3.26-1+debu8u10_amd64.deb 901d24ceb0337afb60244770c6feb3bc 241930 libdevel optional libnss3-dev_3.26-1+debu8u10_amd64.deb 7a9e39f8b4aa60d7c20e918c93e6bbf3 8198842 debug extra libnss3-dbg_3.26-1+debu8u10_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl4Tt8FfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hk3KEP/0hq6oa5/mPdj22MSEh6ynP/1kBcEVH53eOg /MHxXZGB4+nGFtGGN2WSf4jp020StJg6rUqKmV3SThwsx3oqIUSqLZC8snnVfcgS V22LBIqhKtOsb4LEeTIuBRsb+KHgiOtgF0m9VSTh6J4Iqv+Wgn5rYeiW9IBRaIu8 EcKc/7us6p69FYr924M8LXk+d3kMLnubBb4vUVxOxX2DT4Jahb8wnjj+eb7/85zA uHCRs/MqIaZFZaoEUaPWzO6UFF1Bmsk+59j9GUqthdMFknUIlIO/cBP/Q6tBZ31o QvWdH1+wcjy4mu0B9y6AjBCLtjYfOhVg9OBPTfBV4NwlWcGOAeWYSpjVimCw/chw HsG3N6VpfHKrG6p3Si6N/LRAQglewsI+gVUOSwmigYfizsOwK7dpNOi8BLYKY1tJ /Gl5xZcJxqUTKERc58v8uyxl5ykSFxtYSy5ZCYBnL7oDqtfieMrNjQnsBQryEx3r q/Cq8uvAHEBexNXMnzwuVJCb37+Uh6udTInLfPP9zzot/fTCFTrHBsg1tCAkv+qF uoDFv0fuNUWRVQ9Nnjq5U8b75sQaVO/goF0hFWVMzxt+Xeml2uNQkqXf4Ywv3/2O BrcFtRpaVMiCNnFs57ip24nWNp8+WGQYngrqLlI3uhQGqxf1ubIiE1M1TA3mDCLz JVkIQnpJ =8p2j -----END PGP SIGNATURE-----