- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3937-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/              Arturo Borrero Gonzalez
October 27, 2024                              https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : nss
Version        : 2:3.61-1+deb11u4
CVE ID         : CVE-2024-0743 CVE-2024-6602 CVE-2024-6609

nss - Network Security Service libraries

This is a set of libraries designed to support cross-platform development
of security-enabled client and server applications. It can support SSLv2
and  v4, TLS, PKCS #5, #7, #11, #12, S/MIME, X.509 v3 certificates and
other security standards.

Among other utilities, this package includes:
  * certutil: manages certificate and key databases (cert7.db and key3.db)
  * modutil: manages the database of PKCS11 modules (secmod.db)
  * pk12util: imports/exports keys and certificates between the cert/key
    databases and files in PKCS12 format.
  * shlibsign: creates .chk files for use in FIPS mode.
  * signtool: creates digitally-signed jar archives containing files and/or
    code.
  * ssltap: proxy requests for an SSL server and display the contents of
    the messages exchanged between the client and server.

CVE-2024-0743

    An unchecked return value in TLS handshake code could have caused
    a potentially exploitable crash.

CVE-2024-6602

    A mismatch between allocator and deallocator could have lead to
    memory corruption.

CVE-2024-6609

    When almost out-of-memory an elliptic curve key which was never
    allocated could have been freed again.

For Debian 11 bullseye, these problems have been fixed in version
2:3.61-1+deb11u4.

We recommend that you upgrade your nss packages.

For the detailed security status of nss please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nss

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-3937-1: nss Security Advisory Updates

October 28, 2024
nss - Network Security Service libraries This is a set of libraries designed to support cross-platform development of security-enabled client and server applications

Summary

This is a set of libraries designed to support cross-platform development
of security-enabled client and server applications. It can support SSLv2
and v4, TLS, PKCS #5, #7, #11, #12, S/MIME, X.509 v3 certificates and
other security standards.

Among other utilities, this package includes:
* certutil: manages certificate and key databases (cert7.db and key3.db)
* modutil: manages the database of PKCS11 modules (secmod.db)
* pk12util: imports/exports keys and certificates between the cert/key
databases and files in PKCS12 format.
* shlibsign: creates .chk files for use in FIPS mode.
* signtool: creates digitally-signed jar archives containing files and/or
code.
* ssltap: proxy requests for an SSL server and display the contents of
the messages exchanged between the client and server.

CVE-2024-0743

An unchecked return value in TLS handshake code could have caused
a potentially exploitable crash.

CVE-2024-6602

A mismatch between allocator and deallocator could have lead to
memory corruption.

CVE-2024-6609

When almost out-of-memory an elliptic curve key which was never
allocated could have been freed again.

For Debian 11 bullseye, these problems have been fixed in version
2:3.61-1+deb11u4.

We recommend that you upgrade your nss packages.

For the detailed security status of nss please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nss

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : nss
Version : 2:3.61-1+deb11u4
CVE ID : CVE-2024-0743 CVE-2024-6602 CVE-2024-6609

Related News