MGASA-2019-0374 - Updated nss packages fix security vulnerability

Publication date: 08 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0374.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-11745

Updated nss packages fix security vulnerability:

Out-of-bounds write when passing an output buffer smaller than the block
size to NSC_EncryptUpdate (CVE-2019-11745).

Also, rootcerts has been updated to 20191126.00

References:
- https://bugs.mageia.org/show_bug.cgi?id=25792
- - https://ubuntu.com/security/notices/USN-4203-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11745

SRPMS:
- 7/core/nss-3.47.1-1.mga7
- 7/core/rootcerts-20191126.00-1.mga7

Mageia 2019-0374: nss security update

Updated nss packages fix security vulnerability: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745)

Summary

Updated nss packages fix security vulnerability:
Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745).
Also, rootcerts has been updated to 20191126.00

References

- https://bugs.mageia.org/show_bug.cgi?id=25792

- - https://ubuntu.com/security/notices/USN-4203-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11745

Resolution

MGASA-2019-0374 - Updated nss packages fix security vulnerability

SRPMS

- 7/core/nss-3.47.1-1.mga7

- 7/core/rootcerts-20191126.00-1.mga7

Severity
Publication date: 08 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0374.html
Type: security
CVE: CVE-2019-11745

Related News