Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 2123-1] New NSS packages fix cryptographic weaknesses (

    From Florian Weimer@1:229/2 to All on Mon Nov 1 20:50:01 2010
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-2123-1 [email protected] http://www.debian.org/security/ Florian Weimer November 01, 2010 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : nss
    Vulnerability : several
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2010-3170 CVE-2010-3173

    Several vulnerabilities have been discovered in Mozilla's Network
    Security Services (NSS) library. The Common Vulnerabilities and
    Exposures project identifies the following problems:

    CVE-2010-3170
    NSS recognizes a wildcard IP address in the subject's Common
    Name field of an X.509 certificate, which might allow
    man-in-the-middle attackers to spoof arbitrary SSL servers via
    a crafted certificate issued by a legitimate Certification
    Authority.

    CVE-2010-3173
    NSS does not properly set the minimum key length for
    Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for
    remote attackers to defeat cryptographic protection mechanisms
    via a brute-force attack.

    For the stable distribution (lenny), these problems have been fixed in
    version 3.12.3.1-0lenny2.

    For the unstable distribution (sid) and the upcoming stable
    distribution (squeeze), these problems have been fixed in version
    3.12.8-1.

    We recommend that you upgrade your NSS packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/n/nss/nss_3.12.3.1-0lenny2.dsc
    Size/MD5 checksum: 1394 908a5e77c32e84069883a3cfb836eb24
    http://security.debian.org/pool/updates/main/n/nss/nss_3.12.3.1-0lenny2.diff.gz
    Size/MD5 checksum: 53696 3d064b2d08ccc6a8ae11e1771379f1c7
    http://security.debian.org/pool/updates/main/n/nss/nss_3.12.3.1.orig.tar.gz
    Size/MD5 checksum: 5320607 750839c9c018a0984fd94f7a9cc3dd7f

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/n/nss/libnss3-dev_3.12.3.1-0lenny2_alpha.deb
    Size/MD5 checksum: 273438 6a97ce0db5683e1b87c2a3debd4f0a2f
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d-dbg_3.12.3.1-0lenny2_alpha.deb
    Size/MD5 checksum: 3049536 4eaec5fabcab56b1fe06c2d6e0fa8574
    http://security.debian.org/pool/updates/main/n/nss/libnss3-tools_3.12.3.1-0lenny2_alpha.deb
    Size/MD5 checksum: 342354 6bb6d7334e986265f9a1f6f0d6778d98
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d_3.12.3.1-0lenny2_alpha.deb
    Size/MD5 checksum: 1207870 d84910b4354cdb1796dd3d5787cdcee8

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d-dbg_3.12.3.1-0lenny2_amd64.deb
    Size/MD5 checksum: 3101238 6350cb985ded4fbc6fb4c65127f586da
    http://security.debian.org/pool/updates/main/n/nss/libnss3-tools_3.12.3.1-0lenny2_amd64.deb
    Size/MD5 checksum: 320840 7cc70e973254a99a76834a7febbadc67
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d_3.12.3.1-0lenny2_amd64.deb
    Size/MD5 checksum: 1071354 1fb1921a73e16bfd2a4dc6925bdb8a7e
    http://security.debian.org/pool/updates/main/n/nss/libnss3-dev_3.12.3.1-0lenny2_amd64.deb
    Size/MD5 checksum: 262634 799e5eb80cf076fe34c9643b8078bb43

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/n/nss/libnss3-dev_3.12.3.1-0lenny2_arm.deb
    Size/MD5 checksum: 254618 0d553164d3d303e096efbac3ab2dcabe
    http://security.debian.org/pool/updates/main/n/nss/libnss3-tools_3.12.3.1-0lenny2_arm.deb
    Size/MD5 checksum: 309000 edc68fa74a8b939293ca23f7aa3a6efd
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d_3.12.3.1-0lenny2_arm.deb
    Size/MD5 checksum: 1011704 9b9e1459b833922e31510cefab0594c0
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d-dbg_3.12.3.1-0lenny2_arm.deb
    Size/MD5 checksum: 2901632 4ad15a531cdf51ef146f3337148a71d2

    armel architecture (ARM EABI)

    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d-dbg_3.12.3.1-0lenny2_armel.deb
    Size/MD5 checksum: 2924760 f06d340c4aa9f4044d5a00df6617e624
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d_3.12.3.1-0lenny2_armel.deb
    Size/MD5 checksum: 1017348 3f72c2cb4d1d39d0fed98acd9d4409c3
    http://security.debian.org/pool/updates/main/n/nss/libnss3-tools_3.12.3.1-0lenny2_armel.deb
    Size/MD5 checksum: 308638 f81fb9ba70eb3e5b8f3117dba5c18a6b
    http://security.debian.org/pool/updates/main/n/nss/libnss3-dev_3.12.3.1-0lenny2_armel.deb
    Size/MD5 checksum: 258562 2b0b270a34ce0bfa9b8d7589782a820d

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/n/nss/libnss3-dev_3.12.3.1-0lenny2_hppa.deb
    Size/MD5 checksum: 262180 5bb31fdc16b4883f42f3d9a8db31b478
    http://security.debian.org/pool/updates/main/n/nss/libnss3-tools_3.12.3.1-0lenny2_hppa.deb
    Size/MD5 checksum: 347268 025014303d4e266c8b3e7260022624e7
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d-dbg_3.12.3.1-0lenny2_hppa.deb
    Size/MD5 checksum: 2946180 aff9d6ce1e1fefe47443116d9791eee7
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d_3.12.3.1-0lenny2_hppa.deb
    Size/MD5 checksum: 1169546 e439f85cb7d5755488283b48c25213bc

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/n/nss/libnss3-tools_3.12.3.1-0lenny2_i386.deb
    Size/MD5 checksum: 303718 a9bdcd4d31a594c196f18b916adcf29c
    http://security.debian.org/pool/updates/main/n/nss/libnss3-dev_3.12.3.1-0lenny2_i386.deb
    Size/MD5 checksum: 259032 77d7d235c8395b14c47033158ca99a12
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d-dbg_3.12.3.1-0lenny2_i386.deb
    Size/MD5 checksum: 2915646 fdf2b28a0b482e9b5310a69e303162a9
    http://security.debian.org/pool/updates/main/n/nss/libnss3-1d_3.12.3.1-0lenny2_i386.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Mon Jun 8 08:26:26 2026
      from Wales, Uk via Telnet
    • Spearb0y
      Mon Jun 8 06:51:02 2026
      from Massachusetts via SSH
    • Krenn
      Mon Jun 8 05:45:38 2026
      from Sydney, Nsw via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 29:43:15
    Calls: 12,108
    Calls today: 8
    Files: 15,006
    Messages: 6,518,245

© >>> Magnum BBS <<<, 2026