-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2015 19:37:12 +0200 Source: nss Binary: libnss3 libnss3-1d libnss3-tools libnss3-dev libnss3-dbg Architecture: source Version: 2:3.17.2-1.1+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: libnss3 - Network Security Service libraries libnss3-1d - Network Security Service libraries - transitional package libnss3-dbg - Debugging symbols for the Network Security Service libraries libnss3-dev - Development files for the Network Security Service libraries libnss3-tools - Network Security Service tools Changes: nss (2:3.17.2-1.1+deb8u1) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * Add 99_CVE-2015-2721.patch patch. CVE-2015-2721: NSS incorrectly permits skipping of ServerKeyExchange. * Add 100_CVE-2015-2730.patch patch. CVE-2015-2730: ECDSA signature validation fails to handle some signatures correctly. Checksums-Sha1: 6f5607998bcf2bcef85634c9d970714db2d9d256 2244 nss_3.17.2-1.1+deb8u1.dsc c518e0726e89210219e3c583bfa08e40fb39385a 6927414 nss_3.17.2.orig.tar.gz b030d8ca3ffb69a9e942210643f23608af024a95 30436 nss_3.17.2-1.1+deb8u1.debian.tar.xz Checksums-Sha256: df6e61245e546598c0a6716060dd19708a6d9ca1ee285b34d5c29f7bfc15024b 2244 nss_3.17.2-1.1+deb8u1.dsc 134929e44e44b968a4883f4ee513a71ae45d55b486cee41ee8e26c3cc84dab8b 6927414 nss_3.17.2.orig.tar.gz 7fb3a66185af6acb05e66128e56a9753aee8055a3e7a648957bc14b387cc407e 30436 nss_3.17.2-1.1+deb8u1.debian.tar.xz Files: b0b60b8d9e0e671ed0287fbe2bb5f40a 2244 libs optional nss_3.17.2-1.1+deb8u1.dsc d3edb6f6c3688b2fde67ec9c9a8c1214 6927414 libs optional nss_3.17.2.orig.tar.gz 0ec9a52bef098c4fb68b06f401c8b6ce 30436 libs optional nss_3.17.2-1.1+deb8u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJV0OETAAoJEAVMuPMTQ89ElAUQAJF8ch2ShdGhZNh2KQbMrKXV TY9kH62kvEwhyMbutIPiLVUgfp/TrQKhWg6OzW3NbgG8/nwR3wEWrBcmg83OFUWH JVIkArhRaXwvzZ1hlULfw5PPCYbdka/R6h4D8agYR/ZtmbvxldtxiJ7ZcfjWNbZd JFWDiWPLEKIPdTh1sKEG+P3DkmiETqwreSKMZpSNkWIv7XWlArLa+Q1n1XbFcOYf HzgvSGvUi6DP7xS4B8GIwwhA3ENdqsLVOLI7rsla7v5pE3Tao894BLj0j1SvcTjm pAl7aaeKDL/SjDI8LRrndXirNcnS2Je7Ej7y/9lghH9d9CaYOswBNPV8yIQhNcH2 VZXs2NSGwFBBTIUzZibKW6EeIH5+6Ff2bN6H3I5BS/zd9ByV6gjO93ceH+x+usDQ TD53Zu2zksJOYC0e5hXqcCJoYOTc+j/Via3EgYGozmNkDEAbBFbtlSOCYAwq1noe gjDIdJKHyft4mFeKqDwtoEGXVLs0O7cpAfE9OL4Y8+2pqf0h+a/gZfkHm0ez5uSC 1XRbRmhL9+rDqlEubo9qGGlb2tE9glMzGkcDwI+EYg+cFZGUh1mtF54Rmus2orqx OonTjjWab9xYvL0zETt2sFptkXyxqAvi7f5zGbKdti7GXLZt62R1hDN2FgZ5l4XI QZw/iNNgizYDlYXmDUvY =ZLaW -----END PGP SIGNATURE-----