Oval Definition:oval:org.opensuse.security:def:64114
Revision Date:2020-12-01Version:1
Title:Security update for mozilla-nspr, mozilla-nss (Important)
Description:

This update for mozilla-nspr, mozilla-nss fixes the following issues:

mozilla-nss was updated to version 3.53.1

- CVE-2020-12402: Fixed a potential side channel attack during RSA key generation (bsc#1173032). - CVE-2020-12399: Fixed a timing attack on DSA signature generation (bsc#1171978). - CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819). - Fixed various FIPS issues in libfreebl3 which were causing segfaults in the test suite of chrony (bsc#1168669). - Fixed an issue where Firefox tab was crashing (bsc#1170908).

Release notes: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.53_release_notes

mozilla-nspr to version 4.25
Family:unixClass:patch
Status:Reference(s):1139083
1141980
1150733
1156767
1159819
1168669
1169746
1170908
1171978
1173022
1175193
1175194
1175476
1175674
1176116
1176256
1176257
1176258
1176259
CVE-2013-0262
CVE-2013-0263
CVE-2015-3225
CVE-2019-12900
CVE-2019-13619
CVE-2019-14562
CVE-2019-17006
CVE-2019-3689
CVE-2020-12399
CVE-2020-12402
CVE-2020-14349
CVE-2020-14350
CVE-2020-15166
CVE-2020-7040
openSUSE-SU-2019:1781-1
openSUSE-SU-2019:1965-1
openSUSE-SU-2019:2435-1
openSUSE-SU-2020:0119-1
openSUSE-SU-2020:1244-1
SUSE-SU-2020:1839-1
SUSE-SU-2020:2714-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise High Availability 15 SP1
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • bzip2-1.0.6-lp151.5.6 is installed
  • OR bzip2-doc-1.0.6-lp151.5.6 is installed
  • OR libbz2-1-1.0.6-lp151.5.6 is installed
  • OR libbz2-1-32bit-1.0.6-lp151.5.6 is installed
  • OR libbz2-devel-1.0.6-lp151.5.6 is installed
  • OR libbz2-devel-32bit-1.0.6-lp151.5.6 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libecpg6-12.4-lp152.3.7 is installed
  • OR libecpg6-32bit-12.4-lp152.3.7 is installed
  • OR libpq5-12.4-lp152.3.7 is installed
  • OR libpq5-32bit-12.4-lp152.3.7 is installed
  • OR postgresql12-12.4-lp152.3.7 is installed
  • OR postgresql12-contrib-12.4-lp152.3.7 is installed
  • OR postgresql12-devel-12.4-lp152.3.7 is installed
  • OR postgresql12-docs-12.4-lp152.3.7 is installed
  • OR postgresql12-llvmjit-12.4-lp152.3.7 is installed
  • OR postgresql12-plperl-12.4-lp152.3.7 is installed
  • OR postgresql12-plpython-12.4-lp152.3.7 is installed
  • OR postgresql12-pltcl-12.4-lp152.3.7 is installed
  • OR postgresql12-server-12.4-lp152.3.7 is installed
  • OR postgresql12-server-devel-12.4-lp152.3.7 is installed
  • OR postgresql12-test-12.4-lp152.3.7 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND ruby2.5-rubygem-rack-2.0.3-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • libfreebl3-3.53.1-58.48 is installed
  • OR libfreebl3-32bit-3.53.1-58.48 is installed
  • OR libfreebl3-hmac-3.53.1-58.48 is installed
  • OR libfreebl3-hmac-32bit-3.53.1-58.48 is installed
  • OR libsoftokn3-3.53.1-58.48 is installed
  • OR libsoftokn3-32bit-3.53.1-58.48 is installed
  • OR libsoftokn3-hmac-3.53.1-58.48 is installed
  • OR libsoftokn3-hmac-32bit-3.53.1-58.48 is installed
  • OR mozilla-nspr-4.25-19.15 is installed
  • OR mozilla-nspr-32bit-4.25-19.15 is installed
  • OR mozilla-nspr-devel-4.25-19.15 is installed
  • OR mozilla-nss-3.53.1-58.48 is installed
  • OR mozilla-nss-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-certs-3.53.1-58.48 is installed
  • OR mozilla-nss-certs-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-devel-3.53.1-58.48 is installed
  • OR mozilla-nss-sysinit-3.53.1-58.48 is installed
  • OR mozilla-nss-sysinit-32bit-3.53.1-58.48 is installed
  • OR mozilla-nss-tools-3.53.1-58.48 is installed
  • BACK