-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 11 Aug 2015 17:44:07 +0200 Source: nss Binary: libnss3 libnss3-1d libnss3-tools libnss3-dev libnss3-dbg Architecture: source amd64 Version: 2:3.14.5-1+deb7u5 Distribution: wheezy-security Urgency: high Maintainer: Maintainers of Mozilla-related packages <pkg-mozilla-maintainers@lists.alioth.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Description: libnss3 - Network Security Service libraries libnss3-1d - Network Security Service libraries - transitional package libnss3-dbg - Debugging symbols for the Network Security Service libraries libnss3-dev - Development files for the Network Security Service libraries libnss3-tools - Network Security Service tools Changes: nss (2:3.14.5-1+deb7u5) wheezy-security; urgency=high . * Non-maintainer upload by the Security Team. * Add CVE-2015-2721.patch patch. CVE-2015-2721: NSS incorrectly permits skipping of ServerKeyExchange. * Add CVE-2015-2730.patch patch. CVE-2015-2730: ECDSA signature validation fails to handle some signatures correctly. Checksums-Sha1: 50d8da1b1842a7aba1084c7b9893454927565081 2234 nss_3.14.5-1+deb7u5.dsc 1812f68140564bb8171f4dc9c8cc28bd420af66d 45604 nss_3.14.5-1+deb7u5.debian.tar.xz 3252665a3c4ef7e06aadde5233973f8c76260aa0 1062926 libnss3_3.14.5-1+deb7u5_amd64.deb 9bae9048905bb98884c2775db0d2a23faaebaab3 20654 libnss3-1d_3.14.5-1+deb7u5_amd64.deb 981bfd305e243b10c32ee2855e58b631e058ff8f 228660 libnss3-tools_3.14.5-1+deb7u5_amd64.deb 9608db982b41b4a77a4d1eb4a34074a1244a50a4 220938 libnss3-dev_3.14.5-1+deb7u5_amd64.deb 870faad8bd1e51e6f2e0c99131b554d4480a0e57 4839192 libnss3-dbg_3.14.5-1+deb7u5_amd64.deb Checksums-Sha256: 9cb9cab5cb53b99acb0365ea983128e3ffe747929ac070fae112d65e6fb9735a 2234 nss_3.14.5-1+deb7u5.dsc 59e945e5552d79f7ccacd38468434b86d2ce1ddf7ec58172adde75e5bdf324b3 45604 nss_3.14.5-1+deb7u5.debian.tar.xz a899235645dd99c4b394919b372278aa91510d0f1917a3b80a800e9ece40333f 1062926 libnss3_3.14.5-1+deb7u5_amd64.deb e37ed9a26fc1011469597c25a2fb6a59b52ee1558f27b2ddb8a792247a396029 20654 libnss3-1d_3.14.5-1+deb7u5_amd64.deb acd87c65018683955a0d60f9c4ff8bb73b64b340f1a3c55f0b4897c76b64b606 228660 libnss3-tools_3.14.5-1+deb7u5_amd64.deb 618a9801a1013caa4a91bed22acd4ba27ccc0ff8b65cdb95b520db4e961c9dd2 220938 libnss3-dev_3.14.5-1+deb7u5_amd64.deb ff4c87afec3750603a53f4e0e4564b20c3d52b3bae400c08682da6e1310d5691 4839192 libnss3-dbg_3.14.5-1+deb7u5_amd64.deb Files: 321c251099c3f18c0bf6dee0d6b17dde 2234 libs optional nss_3.14.5-1+deb7u5.dsc 5eab7b1874551e663cf12a8cbed0c2b1 45604 libs optional nss_3.14.5-1+deb7u5.debian.tar.xz f1f3f6464d589f81396f1014cee839fd 1062926 libs optional libnss3_3.14.5-1+deb7u5_amd64.deb 20056fd0aae57de99a50435a2c42ecac 20654 oldlibs extra libnss3-1d_3.14.5-1+deb7u5_amd64.deb 093b2d9495935957550f6776e075293a 228660 admin optional libnss3-tools_3.14.5-1+deb7u5_amd64.deb caa8924856d84d64a4d26d5ce2c8ddfd 220938 libdevel optional libnss3-dev_3.14.5-1+deb7u5_amd64.deb 70619f604b9efb12d85f52d64630963b 4839192 debug extra libnss3-dbg_3.14.5-1+deb7u5_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJV0NbRAAoJEAVMuPMTQ89EOQ4P/3O7/2zTf+kMXnzowN8uAfG/ BBWlMeM9v2zK8sGL+tt49r59EfBuutN3dVSSCKAubgSfSgVC2HjlKSD1fTMqIUIz JbEwxsU6bdZg7DcTjifJ7fxqAJhw0ZjfVx9/+mNUIn36dnYWxad9DyJEAjgV9pZk WMpwkmp5px1sNrhFMCVLo6ylQD190E8WLEBYUKY2IXuHjslT1P/2dDDQt1PBNoBU lNUpf88Qd7VRdQsb4HPIm0VBxPZYMHikqI5YEM5xT7BmnJbwZk1uGVNHa10Pc6e+ azmfUA9qzu5uLtgJ0z7AlpwKsumVKyBnb+B4N0JYF1LDXmb5ycA/DCSfOT30VSz5 iBq+EHMvPeojPWL7N1fEaEcJgju74cx6qX3gqWgsd+qeQXQKaZzwQAh6tHJtTM01 un2S0pIPqg/oWDKboEtXdDDj8nnV23d3KFVOx+hwksQpzqrnXNIapED05r/d7i6l y25vJRGVh1etl3Ag9s6EQjSLOZNjTHRYPTzTXvmdEk1UyXU11lPBT+9D+/jLfFii x8D7V6ojEZp/XO333vB5mvXpqWpNaue/8VUTRde/8PDO+j+L1+ir12n95t9Yk3qx wCyK6yqNF7x5EyMaIIgen6++N8Y4SWq8iZBTfTKBVz9fH8naRjFHdt0vZPpn8+sk 0fzSgu/pV25GkUtkpp3k =8RY+ -----END PGP SIGNATURE-----