New Debian nss 2:3.26.2-1.1+deb9u3 fixes: This update addresses the following issue: * Memory corruption in decodeECorDsaSignature with DSA signatures (and RSA-PSS) (CVE-2021-43527)
--- mirror/ftp/4.4/unmaintained/4.4-7/source/nss_3.26.2-1.1+deb9u2.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/nss_3.26.2-1.1+deb9u3.dsc @@ -1,3 +1,8 @@ +2:3.26.2-1.1+deb9u3 [Thu, 02 Dec 2021 17:05:48 +0530] Utkarsh Gupta <utkarsh@debian.org>: + + * Non-maintainer upload by the LTS team. + * Add patch to fix CVE-2021-43527. + 2:3.26.2-1.1+deb9u2 [Tue, 29 Sep 2020 16:33:20 +0300] Adrian Bunk <bunk@debian.org>: * Non-maintainer upload by the LTS team. <http://piuparts.knut.univention.de/4.4-8/#1237137892646016236>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] 6a9bd3d936 Bug #54198: nss 2:3.26.2-1.1+deb9u3 doc/errata/staging/nss.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
Reopen + import new version: DLA-2836-1 was rolled out, fixing CVE-2021-43527 in nss, but that lead to a regression, preventing SSL connections in Chromium. The complete bug report could be found here: https://bugs.debian.org/1001219. For Debian 9 stretch, this problem has been fixed in version 2:3.26.2-1.1+deb9u4.
--- mirror/ftp/4.4/unmaintained/4.4-7/source/nss_3.26.2-1.1+deb9u2.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/nss_3.26.2-1.1+deb9u4.dsc @@ -1,3 +1,14 @@ +2:3.26.2-1.1+deb9u4 [Tue, 07 Dec 2021 14:08:03 +0530] Utkarsh Gupta <utkarsh@debian.org>: + + * Non-maintainer upload by the LTS team. + * Add missing breaks; in secvfy.c to fix + regressions w/ ssl connections. (Closes: #1001219) + +2:3.26.2-1.1+deb9u3 [Thu, 02 Dec 2021 17:05:48 +0530] Utkarsh Gupta <utkarsh@debian.org>: + + * Non-maintainer upload by the LTS team. + * Add patch to fix CVE-2021-43527. + 2:3.26.2-1.1+deb9u2 [Tue, 29 Sep 2020 16:33:20 +0300] Adrian Bunk <bunk@debian.org>: * Non-maintainer upload by the LTS team. <http://piuparts.knut.univention.de/4.4-8/#1237137892642768661>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] 57d6bf66fd Bug #54198: yaml doc/errata/staging/nss.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [4.4-8] 6a9bd3d936 Bug #54198: nss 2:3.26.2-1.1+deb9u3 doc/errata/staging/nss.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1120>