[ubuntu/focal-updates] nss 2:3.49.1-1ubuntu1.8 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Thu Jul 7 12:28:35 UTC 2022


nss (2:3.49.1-1ubuntu1.8) focal-security; urgency=medium

  * SECURITY UPDATE: Crash when handling empty pkcs7 sequence
    - debian/patches/CVE-2022-22747.patch: check for missing signedData
      field in nss/gtests/certdb_gtest/decode_certs_unittest.cc,
      nss/lib/pkcs7/certread.c.
    - CVE-2022-22747
  * SECURITY UPDATE: Free of uninitialized pointer in lg_init
    - debian/patches/CVE-2022-34480.patch: rearrange frees in
      nss/lib/softoken/legacydb/lginit.c.
    - CVE-2022-34480

Date: 2022-07-06 13:28:22.433859+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/nss/2:3.49.1-1ubuntu1.8
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list