nss 2:3.49.1-1ubuntu1.4 source package in Ubuntu
Changelog
nss (2:3.49.1-1ubuntu1.4) focal-security; urgency=medium * SECURITY UPDATE: Side-channel attack - debian/patches/CVE-2020-12400-and-6829-*.patch: use constant-time P-384 and P-521 in nss/lib/freebl/ecl/ecl-priv.h, nss/lib/freebl/ecl/ecl.c, nss/lib/freebl/ecl/ecl_spec384r1.c, nss/lib/freebl/freebl_base.gypi, nss/lib/freebl/manifest.mn, nss/test/ec/ectest.sh. - CVE-2020-12400 - CVE-2020-6829 * SECURITY UPDATE: Timing attack mitigation bypass - debian/patches/CVE-2020-12401.patch: remove unnecessary scalar padding in nss/lib/freebl/ec.c. - CVE-2020-12401 -- <email address hidden> (Leonidas S. Barbosa) Wed, 05 Aug 2020 15:28:48 -0300
Upload details
- Uploaded by:
- Leonidas S. Barbosa
- Uploaded to:
- Focal
- Original maintainer:
- Ubuntu Developers
- Architectures:
- any
- Section:
- libs
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
nss_3.49.1.orig.tar.gz | 72.9 MiB | d9aa42e49e02bb0dc0a2f164604cfc718e11a2a06ddb266cd676376ac21b026e |
nss_3.49.1-1ubuntu1.4.debian.tar.xz | 190.9 KiB | a95160b69d4d08c60af9fbabe683bd4879b3e0f3bddbced265aefb081690085d |
nss_3.49.1-1ubuntu1.4.dsc | 2.2 KiB | 59322a499b19c77cb6024c01b68fa525d5b0cc93e7a7b4d03d9fc507d1468f27 |
Available diffs
Binary packages built by this source
- libnss3: Network Security Service libraries
This is a set of libraries designed to support cross-platform development
of security-enabled client and server applications. It can support SSLv2
and v4, TLS, PKCS #5, #7, #11, #12, S/MIME, X.509 v3 certificates and
other security standards.
- libnss3-dbgsym: debug symbols for libnss3
- libnss3-dev: Development files for the Network Security Service libraries
This is a set of libraries designed to support cross-platform development
of security-enabled client and server applications. It can support SSLv2
and v4, TLS, PKCS #5, #7, #11, #12, S/MIME, X.509 v3 certificates and
other security standards.
.
Install this package if you wish to develop your own programs using the
Network Security Service Libraries.
- libnss3-tools: Network Security Service tools
This is a set of tools on top of the Network Security Service libraries.
This package includes:
* certutil: manages certificate and key databases (cert7.db and key3.db)
* modutil: manages the database of PKCS11 modules (secmod.db)
* pk12util: imports/exports keys and certificates between the cert/key
databases and files in PKCS12 format.
* shlibsign: creates .chk files for use in FIPS mode.
* signtool: creates digitally-signed jar archives containing files and/or
code.
* ssltap: proxy requests for an SSL server and display the contents of
the messages exchanged between the client and server.
- libnss3-tools-dbgsym: debug symbols for libnss3-tools