Ubuntu security notices
USN-3029-1: NSS vulnerability
USN-3029-1: NSS vulnerability Ubuntu Security Notice USN-3029-1 11th July, 2016 nss vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary NSS could be made to crash or run programs if it processed specially crafted network traffic. Software description nss – Network Security Service library Details Tyson Smith and Jed Davis discovered that NSS incorrectly handled memory. Aremote attacker could use this issue to cause NSS to crash, resulting in adenial of service, or possibly execute arbitrary code. This update refreshes the NSS package to version 3.23 which includesthe latest CA certificate bundle. As a security improvement, this updatealso modifies NSS behaviour to reject DH key sizes below 1024 bits,preventing a possible downgrade attack. Update instructions The problem can be corrected by updating your system to [ more… ]