UbuntuUpdates.org

Package "libnss3"

Name: libnss3

Description:

Network Security Service libraries

Latest version: 2:3.98-0ubuntu0.23.10.1
Release: mantic (23.10)
Level: security
Repository: main
Head package: nss
Homepage: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS

Links


Download "libnss3"


Other versions of "libnss3" in Mantic

Repository Area Version
base main 2:3.92-1
updates main 2:3.98-0ubuntu0.23.10.1

Changelog

Version: 2:3.98-0ubuntu0.23.10.1 2024-04-10 16:06:58 UTC

  nss (2:3.98-0ubuntu0.23.10.1) mantic-security; urgency=medium

  * Updated to upstream 3.98 to fix security issues and get a new CA
    certificate bundle.
    - CVE-2023-5388: timing issue in RSA operations
    - CVE-2023-6135: side-channel in multiple NSS NIST curves
  * debian/libnss3.symbols: added new symbol.

 -- Marc Deslauriers <email address hidden> Thu, 21 Mar 2024 09:44:10 -0400

CVE-2023-5388 NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the pr
CVE-2023-6135 Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the



About   -   Send Feedback to @ubuntu_updates