Oval Definition:oval:com.redhat.rhba:def:20150926
Revision Date:2015-05-05Version:638
Title:RHBA-2015:0926: nss, nss-util, and nspr bug fix and enhancement update (Low)
Description:Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities.

  • The nss and nss-util packages have been upgraded to upstream versions 3.18, and the nspr packages have been upgraded to upstream version 4.10.8. The upgraded versions provide a number of bug fixes and enhancements over the previous versions. Notably, these upgrades allow users to upgrade to Mozilla Firefox 38 Extended Support Release. (BZ#1205064, BZ#1205065, BZ#1207052)

    This update also fixes the following bugs:

  • Previously, a race condition in NSS in some cases caused heavily threaded applications, such as the ns-slapd daemon, to terminate unexpectedly when under load. This update fixes the underlying cause, and the described crash no longer occurs. (BZ#1182902)

  • When using version 3.16.1-4 of the nss packages, NSS returned different cipher suites than the prior versions of NSS. This caused certain applications that add external constraints to the cipher suites, such as the Lightweight Directory Access Protocol server (LDAPS), to fail. With this update, the cipher suites table in the /nss/lib/ssl/ssl3con.c file has been adjusted to be compatible with the previous version of NSS, and the affected applications now work as expected. (BZ#1202488)

    Users of nss, nss-util, and nspr are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2014-1569
    RHBA-2015:0926
    RHBA-2015:0926-01
    RHBA-2015:0926-01
    RHBA-2015:0926
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • nspr is earlier than 0:4.10.8-1.el6_6
  • AND nspr is signed with Red Hat redhatrelease2 key
  • nspr-devel is earlier than 0:4.10.8-1.el6_6
  • AND nspr-devel is signed with Red Hat redhatrelease2 key
  • nss-util is earlier than 0:3.18.0-1.el6_6
  • AND nss-util is signed with Red Hat redhatrelease2 key
  • nss-util-devel is earlier than 0:3.18.0-1.el6_6
  • AND nss-util-devel is signed with Red Hat redhatrelease2 key
  • nss is earlier than 0:3.18.0-5.3.el6_6
  • AND nss is signed with Red Hat redhatrelease2 key
  • nss-devel is earlier than 0:3.18.0-5.3.el6_6
  • AND nss-devel is signed with Red Hat redhatrelease2 key
  • nss-pkcs11-devel is earlier than 0:3.18.0-5.3.el6_6
  • AND nss-pkcs11-devel is signed with Red Hat redhatrelease2 key
  • nss-sysinit is earlier than 0:3.18.0-5.3.el6_6
  • AND nss-sysinit is signed with Red Hat redhatrelease2 key
  • nss-tools is earlier than 0:3.18.0-5.3.el6_6
  • AND nss-tools is signed with Red Hat redhatrelease2 key
  • BACK