[ubuntu/groovy-proposed] nss 2:3.49.1-1ubuntu2 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Wed Jun 10 18:03:18 UTC 2020


nss (2:3.49.1-1ubuntu2) groovy; urgency=medium

  * SECURITY UPDATE: Timing attack during DSA key generation
    - debian/patches/CVE-2020-12399.patch: force a fixed length for DSA
      exponentiation in nss/lib/freebl/dsa.c.
    - CVE-2020-12399

Date: Wed, 10 Jun 2020 12:54:12 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/nss/2:3.49.1-1ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 10 Jun 2020 12:54:12 -0400
Source: nss
Architecture: source
Version: 2:3.49.1-1ubuntu2
Distribution: groovy
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 nss (2:3.49.1-1ubuntu2) groovy; urgency=medium
 .
   * SECURITY UPDATE: Timing attack during DSA key generation
     - debian/patches/CVE-2020-12399.patch: force a fixed length for DSA
       exponentiation in nss/lib/freebl/dsa.c.
     - CVE-2020-12399
Checksums-Sha1:
 328a01ac62a4b5d9f58acb44868ab0a388c7ce81 2276 nss_3.49.1-1ubuntu2.dsc
 c1bdfa44fc8e96bd925c817985ec542a45ae33ed 25824 nss_3.49.1-1ubuntu2.debian.tar.xz
 78ae2d92bef6f46eb082e8361509bb3839c54cd9 5803 nss_3.49.1-1ubuntu2_source.buildinfo
Checksums-Sha256:
 701d8a551facf0a2e19502c696f294d48a9e2478644fab52953ce36fe628b442 2276 nss_3.49.1-1ubuntu2.dsc
 37de2e1772347b64cbeeb8b29586d4547431e1dbd6d873af70c596ea39581397 25824 nss_3.49.1-1ubuntu2.debian.tar.xz
 14ada5ca721ef1206c132366f547bc2bddf77dc115ab4b5d74afeeeb1d7d45d7 5803 nss_3.49.1-1ubuntu2_source.buildinfo
Files:
 aeafbf732b1d7b9988891dd0f967e43b 2276 libs optional nss_3.49.1-1ubuntu2.dsc
 e6093730da0007d094eff866eb902a38 25824 libs optional nss_3.49.1-1ubuntu2.debian.tar.xz
 5936da620a94273610ec03c51bc81d01 5803 libs optional nss_3.49.1-1ubuntu2_source.buildinfo
Original-Maintainer: Maintainers of Mozilla-related packages <team+pkg-mozilla at tracker.debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl7hHxoACgkQZWnYVadE
vpM+ig//SVOchw4ZKC1Nl5uxPYnrzV2o0V8AOY4cTtfEo/vD8jmksNit8wwa2OaI
WkeGBUwq7n9ObDa1o/4NTO2uWNP3xPFEYXEHwyASwCWhowlKC9xRK5nJq8x4Wy0g
aUy+l3E0l45tKp3FlaLI358EX/F/Yt/MnyVqb3hKrvPUDQCPPha/uwfNRuUNYNAg
9H9mqT/v+6EJR0xIKYKg9dIH6skmycoJ7Jr+3gN8F0sdUDsmuJK4D9HR17mDFVZt
QDgc209sDoBMifGRrklolgYrkoVeEgm2rzkpO+fduM0/Wv3Tl4NDgx327ftYhLXT
sCIY3FEoUv1Ol5lxomivwSL3MDtR1Hg/axy5XFRI9bd9FUK8T14Yjy/WpNAj83aL
SP7iD4wYMpftkYwf3BlaVknj58gTtleRcxO9tqfDTyG5GmdMqywwO06LGBP/BRME
ds33KjpJxY7bTlcSoLvrJUwPK5PtR2On5IhB+t0d2xwSFSYff84bfzHxgrpzg/9p
R07QpLahYwwR2n2Ze+2vgRoBcST347/F0TQzU5uju7jJXGQTMKZXUYlc6h9MogZp
3r37vGXjtQf3YOJTF7EMbErABOK7HItrFss/cev0GH10mhhBCj3J1h3GNe49n1ez
WGHMp30XWvxFpB48MnApceWhSI4Wc0kh8O7A4cEL/RcYQ4dwExU=
=oC99
-----END PGP SIGNATURE-----


More information about the Groovy-changes mailing list