nspr-4.9.5-2.AXS3, nss-3.14.3-18.AXS3

エラータID: AXSA:2013-664:03

Release date: 
Monday, October 21, 2013 - 13:26
Subject: 
nspr-4.9.5-2.AXS3, nss-3.14.3-18.AXS3
Affected Channels: 
Asianux Server 3 for x86_64
Asianux Server 3 for x86
Severity: 
High
Description: 

nss Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSL v2 and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509 v3 certificates, and other security standards.

nspr NSPR provides platform independence for non-GUI operating system facilities. These facilities include threads, thread synchronization, normal file and network I/O, interval timing and calendar time, basic memory management (malloc and free) and shared library linking.

Security issues fixed with this release:

• CVE-2013-0791
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.

• CVE-2013-1620
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Fixed bugs:

• Previously, a defect in the FreeBL library implementation of the Diffie-Hellman (DH) protocol caused Openswan to drop connections; this has been fixed.

• Fixed a memory leak in the nssutil_ReadSecmodDB() function.

• nss now protects itself against being called before it has been properly initialized by the caller.

• Previously the certutil -H command did not describe the -F option. This has been fixed.

• Previously, a bug in the FreeBL library made the Openswan application generate a Key Exchange payload that was one byte shorter than what was required by the Diffie Hellman (DH) protocol, and Openswan would drop connections. This has been fixed.

• Previously, the remote-viewer utility failed to utilize a plugged-in smart card reader when a Spice client was running and the client could eventually crash. This has been fixed.

• Incorporated various GCM code fixes.

Enhancement:

• Added support for the NIST Suite B set of recommended algorithms for Elliptic Curve Cryptography.

After installation, applications using NSS or NSPR must be restarted for this update to take effect.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

Asianux Server 3 for x86
  1. nss-3.14.3-18.AXS3.i386.rpm
    MD5: 7dca2f1010afad3d936d92a108bae4e0
    SHA-256: acefabc7ec94e1c62f918b448e5ceb0c1c5174d81823ecbb26bbb544af0b5329
    Size: 1.23 MB
  2. nss-devel-3.14.3-18.AXS3.i386.rpm
    MD5: 56f3b997a0704651f8ce06c2bcb08e0c
    SHA-256: 7075d71e4369e3af0a3597acc4f68d032e1a58c3a71069661157288352c1fcaf
    Size: 247.40 kB
  3. nss-tools-3.14.3-18.AXS3.i386.rpm
    MD5: b18070df82570443877c2d1d3aecd5cb
    SHA-256: 66349749141a9d0d1eba575c90d71681ec993d68b532917b9f0e16b05a6e1c31
    Size: 709.63 kB

Asianux Server 3 for x86_64
  1. nss-3.14.3-18.AXS3.x86_64.rpm
    MD5: eb20e4fe0459b081f0d2bd4c5b40a3f5
    SHA-256: f5fdcbbc2ebbe8de7e4774fa8c4866be465c9f655545fa0cc648dabc8de449b9
    Size: 1.24 MB
  2. nss-devel-3.14.3-18.AXS3.x86_64.rpm
    MD5: 59c8224a162b01179b6f644dd46231a4
    SHA-256: afc08cb0a86b12068260f24457a423d5548fd374e192a01dbc728b504fb3511d
    Size: 247.47 kB
  3. nss-tools-3.14.3-18.AXS3.x86_64.rpm
    MD5: 390ddb696e77dee52271c75cd5913434
    SHA-256: ca8ecf53ae27afa2c90d3542fa2336a13177592c4ae90f92b5299ee9b4477c38
    Size: 716.19 kB