nss-3.12.10-17.0.1.AXS4, nss-util-3.12.10-2.AXS4, nspr-4.8.8-3.AXS4, nss-softokn-3.12.9-11.AXS4
エラータID: AXSA:2012-59:01
NSPR provides platform independence for non-GUI operating system facilities. These facilities include threads, thread synchronization, normal file and network I/O, interval timing and calendar time, basic memory management (malloc and free) and shared library linking.
Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSL v2 and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3 certificates, and other security standards.
Network Security Services Softoken Cryptographic Module
Utilities for Network Security Services and the Softoken module
Security issues fixed with this release:
- The Malaysia-based Digicert Sdn. Bhd. subordinate Certificate Authority (CA) issued HTTPS certificates with weak keys. This update renders any HTTPS certificates signed by that CA as untrusted for all uses (SSL, S/MIME, and code signing). This only applies to applications using the NSS Builtin Object Token. Application using the NSS library but not the NSS Builtin Object Token are not targeted.
Fixed bugs:
- A problem where applications could not use multiple SSL client certificates in the same process had been re-introduced with the recent changes to NSS. A new patch has been added, fixing this bug.
- Fixed an infinite loop leading to a stack overflow in the CMS message decoder: it would lose the pointer to enveloped data contained in a CMS encoded message when decoding it.
- The CMS routines failed to verify signed data when the SignerInfo object was using a subjectKeyID extension to indicate the signer: it returned the following:
signer 0 status = SigningCertNotFound
cmsutil: problem decoding: Unrecognized Object Identifier.
This has been fixed and the verification now succeeds.
- Due to insufficient permissions, when running debug builds, the pen module sometimes terminated with a segmentation fault when trying to write its log. This has been fixed.
- Fixed the generateCRMFRequest tool: it could not produce an RSA key larger than 2048.
- On 64-bit CPUs with native AES instruction support, the intel_aes_decrypt_cbc_256() function failed with the message data mismatch when input and output buffers were the same. This has been fixed.
- Updated the health tests for deterministic random bit generator (DRBG) to meet FIPS requirements.
- On NSS initialization even if the module loader was not adding any persistent certificate or module databases, it incorrectly initialized the PKCS#11 module: trying to synchronize usernames and passwords on an IPA server with data on an Active Directory server would then fail with the error {'desc': Can't contact LDAP server}. This has been fixed.
Enhancements:
- Added support for pluggable ECC (Error-Correcting Code) memory.
- The nss-softokn, nss-util, nss, and nspr libraries have been built with partial RELRO support (-Wl,-z,relro).
Update packages.
N/A
SRPMS
- nspr-4.8.8-3.AXS4.src.rpm
MD5: a438f350e3c1c1f3df8960c445d13eea
SHA-256: eabb899be149e9c25077320f131ba93005f01b89cd254f8302b16987d1ae66ed
Size: 898.64 kB - nss-softokn-3.12.9-11.AXS4.src.rpm
MD5: f2383b7c9684150383d8bfa069dbfc42
SHA-256: 7336888f9f278c48ec81c9cef45a5214cf982866ac3a3ae2df16eeefb8ce6347
Size: 1.03 MB - nss-util-3.12.10-2.AXS4.src.rpm
MD5: c4ac51f38dba9b252bc45c98b912b351
SHA-256: 4c015d3afae5f5ff9927d396286fb7c81fea79f41d367b9a07ac48851e779083
Size: 275.54 kB - nss-3.12.10-17.0.1.AXS4.src.rpm
MD5: bcdc7a6296a48e0081858b0be355974d
SHA-256: 06908adbbe4d6e33697de9fbb4d1472ad76b28a96f90b41eb7b860499a62dc24
Size: 4.40 MB
Asianux Server 4 for x86
- nspr-4.8.8-3.AXS4.i686.rpm
MD5: c9f2ae81f9f06f8bb6cd56d4f450eb38
SHA-256: b4638c94af7de117d057b4eba0a85f88ef9065b87c406be66ae6138c40ec9123
Size: 112.29 kB - nspr-devel-4.8.8-3.AXS4.i686.rpm
MD5: 294430f549d01696d5bcb863b74c939e
SHA-256: bed800788bb282f72e2b46dc5d7d0e1abc387763d86baa976e0f1e48c043dee2
Size: 108.45 kB - nss-util-3.12.10-2.AXS4.i686.rpm
MD5: d7284776e15228f9027f99e33395d89c
SHA-256: 592984749c83254d1f59c8507ac3dabdd72ec0bc09bd8c4e5d7e661c38f2edb8
Size: 45.48 kB - nss-util-devel-3.12.10-2.AXS4.i686.rpm
MD5: c2be566d3970fdbb2ae5a1c4a47507d1
SHA-256: fd6baaf229b83ae261d2bba20515940924386f638a19686f2bae3085acd9f721
Size: 58.80 kB
Asianux Server 4 for x86_64
- nspr-4.8.8-3.AXS4.x86_64.rpm
MD5: f0e7fd5383b95783353677f27548d0e4
SHA-256: 0c92182f77cc7b97b683975298b7b2c3bf9560cbbf2f75bb362399edfdc9598a
Size: 109.21 kB - nspr-devel-4.8.8-3.AXS4.x86_64.rpm
MD5: b52c4b5ff1513b13afa9a14e358ca314
SHA-256: fff9f8b22d3b51c92197c1914123566dd9e45b079557cfcd2c1a60b70adcf4f4
Size: 108.03 kB - nspr-4.8.8-3.AXS4.i686.rpm
MD5: c9f2ae81f9f06f8bb6cd56d4f450eb38
SHA-256: b4638c94af7de117d057b4eba0a85f88ef9065b87c406be66ae6138c40ec9123
Size: 112.29 kB - nspr-devel-4.8.8-3.AXS4.i686.rpm
MD5: 294430f549d01696d5bcb863b74c939e
SHA-256: bed800788bb282f72e2b46dc5d7d0e1abc387763d86baa976e0f1e48c043dee2
Size: 108.45 kB - nss-util-3.12.10-2.AXS4.x86_64.rpm
MD5: e5c930a045c2b710fe45ba459471e4f2
SHA-256: 37b2a1576418bf3d87d6879463d87d44da060cd78521737b81dff7184b2dc204
Size: 45.14 kB - nss-util-devel-3.12.10-2.AXS4.x86_64.rpm
MD5: 085f60c2488bed73172726c203970a39
SHA-256: fef6a8102053ca6c1cd559c2450c455595c16303031cf4d521dfd1434aae0c84
Size: 58.35 kB - nss-util-3.12.10-2.AXS4.i686.rpm
MD5: d7284776e15228f9027f99e33395d89c
SHA-256: 592984749c83254d1f59c8507ac3dabdd72ec0bc09bd8c4e5d7e661c38f2edb8
Size: 45.48 kB - nss-util-devel-3.12.10-2.AXS4.i686.rpm
MD5: c2be566d3970fdbb2ae5a1c4a47507d1
SHA-256: fd6baaf229b83ae261d2bba20515940924386f638a19686f2bae3085acd9f721
Size: 58.80 kB