SUSE-SU-2019:3395-1: moderate: Security update for mozilla-nspr, mozilla-nss

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Mon Dec 30 10:11:22 MST 2019


   SUSE Security Update: Security update for mozilla-nspr, mozilla-nss
______________________________________________________________________________

Announcement ID:    SUSE-SU-2019:3395-1
Rating:             moderate
References:         #1141322 #1158527 #1159819 
Cross-References:   CVE-2018-18508 CVE-2019-11745 CVE-2019-17006
                   
Affected Products:
                    SUSE Linux Enterprise Module for Server Applications 15-SP1
                    SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1
                    SUSE Linux Enterprise Module for Basesystem 15-SP1
                    SUSE Linux Enterprise Module for Basesystem 15
______________________________________________________________________________

   An update that fixes three vulnerabilities is now available.

Description:

   This update for mozilla-nspr, mozilla-nss fixes the following issues:

   mozilla-nss was updated to NSS 3.47.1:

   Security issues fixed:

   - CVE-2019-17006: Added length checks for cryptographic primitives
     (bsc#1159819).
   - CVE-2019-11745: EncryptUpdate should use maxout, not block size
     (bsc#1158527).
   - CVE-2019-11727: Fixed vulnerability sign CertificateVerify with PKCS#1
     v1.5 signatures issue (bsc#1141322).

   mozilla-nspr was updated to version 4.23:

   - Whitespace in C files was cleaned up and no longer uses tab characters
     for indenting.


Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Module for Server Applications 15-SP1:

      zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2019-3395=1

   - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1:

      zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-3395=1

   - SUSE Linux Enterprise Module for Basesystem 15-SP1:

      zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2019-3395=1

   - SUSE Linux Enterprise Module for Basesystem 15:

      zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-3395=1



Package List:

   - SUSE Linux Enterprise Module for Server Applications 15-SP1 (aarch64 ppc64le s390x x86_64):

      libfreebl3-hmac-3.47.1-3.22.1
      libsoftokn3-hmac-3.47.1-3.22.1
      mozilla-nss-debuginfo-3.47.1-3.22.1
      mozilla-nss-debugsource-3.47.1-3.22.1

   - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (x86_64):

      libfreebl3-hmac-32bit-3.47.1-3.22.1
      libsoftokn3-hmac-32bit-3.47.1-3.22.1
      mozilla-nss-32bit-debuginfo-3.47.1-3.22.1
      mozilla-nss-debugsource-3.47.1-3.22.1
      mozilla-nss-sysinit-32bit-3.47.1-3.22.1
      mozilla-nss-sysinit-32bit-debuginfo-3.47.1-3.22.1

   - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64):

      libfreebl3-3.47.1-3.22.1
      libfreebl3-debuginfo-3.47.1-3.22.1
      libsoftokn3-3.47.1-3.22.1
      libsoftokn3-debuginfo-3.47.1-3.22.1
      mozilla-nspr-4.23-3.9.1
      mozilla-nspr-debuginfo-4.23-3.9.1
      mozilla-nspr-debugsource-4.23-3.9.1
      mozilla-nspr-devel-4.23-3.9.1
      mozilla-nss-3.47.1-3.22.1
      mozilla-nss-certs-3.47.1-3.22.1
      mozilla-nss-certs-debuginfo-3.47.1-3.22.1
      mozilla-nss-debuginfo-3.47.1-3.22.1
      mozilla-nss-debugsource-3.47.1-3.22.1
      mozilla-nss-devel-3.47.1-3.22.1
      mozilla-nss-sysinit-3.47.1-3.22.1
      mozilla-nss-sysinit-debuginfo-3.47.1-3.22.1
      mozilla-nss-tools-3.47.1-3.22.1
      mozilla-nss-tools-debuginfo-3.47.1-3.22.1

   - SUSE Linux Enterprise Module for Basesystem 15-SP1 (x86_64):

      libfreebl3-32bit-3.47.1-3.22.1
      libfreebl3-32bit-debuginfo-3.47.1-3.22.1
      libsoftokn3-32bit-3.47.1-3.22.1
      libsoftokn3-32bit-debuginfo-3.47.1-3.22.1
      mozilla-nspr-32bit-4.23-3.9.1
      mozilla-nspr-32bit-debuginfo-4.23-3.9.1
      mozilla-nss-32bit-3.47.1-3.22.1
      mozilla-nss-32bit-debuginfo-3.47.1-3.22.1
      mozilla-nss-certs-32bit-3.47.1-3.22.1
      mozilla-nss-certs-32bit-debuginfo-3.47.1-3.22.1

   - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64):

      libfreebl3-3.47.1-3.22.1
      libfreebl3-debuginfo-3.47.1-3.22.1
      libfreebl3-hmac-3.47.1-3.22.1
      libsoftokn3-3.47.1-3.22.1
      libsoftokn3-debuginfo-3.47.1-3.22.1
      libsoftokn3-hmac-3.47.1-3.22.1
      mozilla-nspr-4.23-3.9.1
      mozilla-nspr-debuginfo-4.23-3.9.1
      mozilla-nspr-debugsource-4.23-3.9.1
      mozilla-nspr-devel-4.23-3.9.1
      mozilla-nss-3.47.1-3.22.1
      mozilla-nss-certs-3.47.1-3.22.1
      mozilla-nss-certs-debuginfo-3.47.1-3.22.1
      mozilla-nss-debuginfo-3.47.1-3.22.1
      mozilla-nss-debugsource-3.47.1-3.22.1
      mozilla-nss-devel-3.47.1-3.22.1
      mozilla-nss-sysinit-3.47.1-3.22.1
      mozilla-nss-sysinit-debuginfo-3.47.1-3.22.1
      mozilla-nss-tools-3.47.1-3.22.1
      mozilla-nss-tools-debuginfo-3.47.1-3.22.1

   - SUSE Linux Enterprise Module for Basesystem 15 (x86_64):

      libfreebl3-32bit-3.47.1-3.22.1
      libfreebl3-32bit-debuginfo-3.47.1-3.22.1
      libfreebl3-hmac-32bit-3.47.1-3.22.1
      libsoftokn3-32bit-3.47.1-3.22.1
      libsoftokn3-32bit-debuginfo-3.47.1-3.22.1
      libsoftokn3-hmac-32bit-3.47.1-3.22.1
      mozilla-nspr-32bit-4.23-3.9.1
      mozilla-nspr-32bit-debuginfo-4.23-3.9.1
      mozilla-nss-32bit-3.47.1-3.22.1
      mozilla-nss-32bit-debuginfo-3.47.1-3.22.1
      mozilla-nss-certs-32bit-3.47.1-3.22.1
      mozilla-nss-certs-32bit-debuginfo-3.47.1-3.22.1


References:

   https://www.suse.com/security/cve/CVE-2018-18508.html
   https://www.suse.com/security/cve/CVE-2019-11745.html
   https://www.suse.com/security/cve/CVE-2019-17006.html
   https://bugzilla.suse.com/1141322
   https://bugzilla.suse.com/1158527
   https://bugzilla.suse.com/1159819



More information about the sle-security-updates mailing list