Debian LTS: DLA-3937-1: nss Security Advisory Updates
Summary
This is a set of libraries designed to support cross-platform development
of security-enabled client and server applications. It can support SSLv2
and v4, TLS, PKCS #5, #7, #11, #12, S/MIME, X.509 v3 certificates and
other security standards.
Among other utilities, this package includes:
* certutil: manages certificate and key databases (cert7.db and key3.db)
* modutil: manages the database of PKCS11 modules (secmod.db)
* pk12util: imports/exports keys and certificates between the cert/key
databases and files in PKCS12 format.
* shlibsign: creates .chk files for use in FIPS mode.
* signtool: creates digitally-signed jar archives containing files and/or
code.
* ssltap: proxy requests for an SSL server and display the contents of
the messages exchanged between the client and server.
CVE-2024-0743
An unchecked return value in TLS handshake code could have caused
a potentially exploitable crash.
CVE-2024-6602
A mismatch between allocator and deallocator could have lead to
memory corruption.
CVE-2024-6609
When almost out-of-memory an elliptic curve key which was never
allocated could have been freed again.
For Debian 11 bullseye, these problems have been fixed in version
2:3.61-1+deb11u4.
We recommend that you upgrade your nss packages.
For the detailed security status of nss please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nss
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS