Oval Definition:
oval:org.opensuse.security:def:126165
Revision Date
:
2020-01-13
Version
:
1
Title
:
Security update for mozilla-nspr, mozilla-nss (Moderate)
Description
:
This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to NSS 3.47.1:
Security issues fixed:
- CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819). - CVE-2019-11745: EncryptUpdate should use maxout, not block size (bsc#1158527). - CVE-2019-11727: Fixed vulnerability sign CertificateVerify with PKCS#1 v1.5 signatures issue (bsc#1141322).
mozilla-nspr was updated to version 4.23:
- Whitespace in C files was cleaned up and no longer uses tab characters for indenting.
Family
:
unix
Class
:
patch
Status
:
Reference(s)
:
1141322
1158527
1159819
CVE-2019-11745
CVE-2019-17006
SUSE-SU-2020:0088-1
Platform(s)
:
SUSE Linux Enterprise Desktop 12 SP4
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Software Development Kit 12 SP4
Product(s)
:
Definition Synopsis
Release Information
SUSE Linux Enterprise Desktop 12 SP4 is installed
OR
SUSE Linux Enterprise Server 12 SP4 is installed
OR
SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
OR
SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
AND
Package Information
mozilla-nspr-devel-4.23-19.12.1 is installed
OR
mozilla-nss-devel-3.47.1-58.34.1 is installed
BACK