Debian Security Update DSA-3998 nss - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,788
Reaction score
74
Credits
-1,257
Martin Thomson discovered that nss, the Mozilla Network Security Service library, is prone to a use-after-free vulnerability in the TLS 1.2 implementation when handshake hashes are generated. A remote attacker can take advantage of this flaw to cause an application using the nss library to crash, resulting in a denial of service, or potentially to execute arbitrary code.

Continue reading...
 


Follow Linux.org

Members online


Latest posts

Top