Oval Definition:oval:org.mitre.oval:def:21929
Revision Date:2014-02-24Version:10
Title:RHSA-2011:1444: nss security update (Important)
Description:Network Security Services (NSS) is a set of libraries designed to supportthe development of security-enabled client and server applications.It was found that the Malaysia-based Digicert Sdn. Bhd. subordinateCertificate Authority (CA) issued HTTPS certificates with weak keys. Thisupdate renders any HTTPS certificates signed by that CA as untrusted. Thiscovers all uses of the certificates, including SSL, S/MIME, and codesigning. Note: Digicert Sdn. Bhd. is not the same company as found atdigicert.com. (BZ#751366)Note: This fix only applies to applications using the NSS Builtin ObjectToken. It does not render the certificates untrusted for applications thatuse the NSS library, but do not use the NSS Builtin Object Token.This update also fixes the following bug on Red Hat Enterprise Linux 5:* When using mod_nss with the Apache HTTP Server, a bug in NSS on Red HatEnterprise Linux 5 resulted in file descriptors leaking each time theApache HTTP Server was restarted with the "service httpd reload" command.This could have prevented the Apache HTTP Server from functioning properlyif all available file descriptors were consumed. (BZ#743508)For Red Hat Enterprise Linux 6, these updated packages upgrade NSS toversion 3.12.10. As well, they upgrade NSPR (Netscape Portable Runtime) toversion 4.8.8 and nss-util to version 3.12.10 on Red HatEnterprise Linux 6, as required by the NSS update. (BZ#735972, BZ#736272,BZ#735973)All NSS users should upgrade to these updated packages, which correct thisissue. After installing the update, applications using NSS must berestarted for the changes to take effect. In addition, on Red HatEnterprise Linux 6, applications using NSPR and nss-util must also berestarted.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2011:1444
RHSA-2011:1444-01
Platform(s):CentOS Linux 5
CentOS Linux 6
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Product(s):
Definition Synopsis
  • Operation system section
  • Redhat 5 or Centos 5 release
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages section
  • nss-tools is earlier than 0:3.12.10-7.el5_7
  • OR nss-pkcs11-devel is earlier than 0:3.12.10-7.el5_7
  • OR nss is earlier than 0:3.12.10-7.el5_7
  • OR nss-devel is earlier than 0:3.12.10-7.el5_7
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND Packages section
  • nss-tools is earlier than 0:3.12.10-2.el6_1
  • OR nss-pkcs11-devel is earlier than 0:3.12.10-2.el6_1
  • OR nss-sysinit is earlier than 0:3.12.10-2.el6_1
  • OR nss is earlier than 0:3.12.10-2.el6_1
  • OR nss-devel is earlier than 0:3.12.10-2.el6_1
  • OR nspr is earlier than 0:4.8.8-1.el6_1
  • OR nspr-devel is earlier than 0:4.8.8-1.el6_1
  • OR nss-util is earlier than 0:3.12.10-1.el6_1
  • OR nss-util-devel is earlier than 0:3.12.10-1.el6_1
  • BACK