-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5062-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso January 25, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nss CVE ID : CVE-2022-22747 Tavis Ormandy discovered that incorrect parsing of pkcs7 sequences in nss, the Mozilla Network Security Service library, may result in denial of service. For the oldstable distribution (buster), this problem has been fixed in version 2:3.42.1-1+deb10u5. For the stable distribution (bullseye), this problem has been fixed in version 2:3.61-1+deb11u2. We recommend that you upgrade your nss packages. For the detailed security status of nss please refer to its security tracker page at: https://security-tracker.debian.org/tracker/nss Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmHwc+lfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Tr6Q//daEqoVUkJVZDJjpaX/HEu8v5bJ6yQoR1/5B8tbP+AceuC/fCXb9Hvv8o /zUeAHGC0i3kdeNcvgf3klsCVWeRcCtspwIeYdFz7tE9kNEYS4Kg0+W9Fh1Dv5fg pHtMLcLQWkQT3evGV0eEggsgRrC2uPUoLtuN1+7vQoSMRLjLR42/xR01ZqmvnQ7z rSIkR7R4QV3mVA+tPQ/crOvgAUe7ivYZuofqjXslwI/3bTo87Cf8+TK5imWfw811 oNIxLFOlk5e/59vUFh24dSdV4lTk3rBQe63Od0LV0icsXQyteAs7jlqIQCW0vwLp v4Q+5fTljHMELHWJtsxvpl3PFzR32+Zz6dlf8daAYSipRjNzTth+iZ+JiBqXhg4i vvCYDPgoma6r6h1IC5IW61lVLUeXhEF9QsR9fmia9geBFnMV3MrHA96txui/7stt pa60CtVW8/0OrvwEJ1xjPXVLY8ZHL3P+oekV1hPp1A+hK9ZDhW/D208bBfu+177g Znnda4+LDsj4wPjvMvJLweDmYbdvT9//A8jYbqvkhKI5fajtBsUvZqjg4umnBvC4 zhYBiaqm3by0k5qwmsxpF2gdsrbo+kug7UD2Mjh2u2mzFu3yGq+pD4bJjNefPJE9 Y85irnPcYa+tKvbGHo8dicrSfo+Tnt49gZRCzCD0rGIzxTiOOow= =635D -----END PGP SIGNATURE-----