[ELSA-2015-1981] nss, nss-util, and nspr security update

Severity Critical
Affected Packages 18
CVEs 3

nspr
[4.10.8-2]
- Resolves: Bug 1269360 - CVE-2015-7183
- nspr: heap-buffer overflow in PL_ARENA_ALLOCATE can lead to crash (under ASAN), potential memory corruption

nss
[3.19.1-5.0.1]
- Added nss-vendor.patch to change vendor

[3.19.1-5]
- Rebuild against updated NSPR

[3.19.1-4]
- Sync up with the rhel-6.6 branch
- Resolves: Bug 1224450

nss-util
[3.19.1-2]
- Resolves: Bug 1269355 - CVE-2015-7182 CVE-2015-7181

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/nss?distro=oraclelinux-7.1 oraclelinux nss < 3.19.1-7.0.1.el7_1.2 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nss?distro=oraclelinux-6.7 oraclelinux nss < 3.19.1-5.0.1.el6_7 oraclelinux-6.7
Affected pkg:rpm/oraclelinux/nss-util?distro=oraclelinux-7.1 oraclelinux nss-util < 3.19.1-4.el7_1 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nss-util?distro=oraclelinux-6.7 oraclelinux nss-util < 3.19.1-2.el6_7 oraclelinux-6.7
Affected pkg:rpm/oraclelinux/nss-util-devel?distro=oraclelinux-7.1 oraclelinux nss-util-devel < 3.19.1-4.el7_1 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nss-util-devel?distro=oraclelinux-6.7 oraclelinux nss-util-devel < 3.19.1-2.el6_7 oraclelinux-6.7
Affected pkg:rpm/oraclelinux/nss-tools?distro=oraclelinux-7.1 oraclelinux nss-tools < 3.19.1-7.0.1.el7_1.2 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nss-tools?distro=oraclelinux-6.7 oraclelinux nss-tools < 3.19.1-5.0.1.el6_7 oraclelinux-6.7
Affected pkg:rpm/oraclelinux/nss-sysinit?distro=oraclelinux-7.1 oraclelinux nss-sysinit < 3.19.1-7.0.1.el7_1.2 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nss-sysinit?distro=oraclelinux-6.7 oraclelinux nss-sysinit < 3.19.1-5.0.1.el6_7 oraclelinux-6.7
Affected pkg:rpm/oraclelinux/nss-pkcs11-devel?distro=oraclelinux-7.1 oraclelinux nss-pkcs11-devel < 3.19.1-7.0.1.el7_1.2 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nss-pkcs11-devel?distro=oraclelinux-6.7 oraclelinux nss-pkcs11-devel < 3.19.1-5.0.1.el6_7 oraclelinux-6.7
Affected pkg:rpm/oraclelinux/nss-devel?distro=oraclelinux-7.1 oraclelinux nss-devel < 3.19.1-7.0.1.el7_1.2 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nss-devel?distro=oraclelinux-6.7 oraclelinux nss-devel < 3.19.1-5.0.1.el6_7 oraclelinux-6.7
Affected pkg:rpm/oraclelinux/nspr?distro=oraclelinux-7.1 oraclelinux nspr < 4.10.8-2.el7_1 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nspr?distro=oraclelinux-6.7 oraclelinux nspr < 4.10.8-2.el6_7 oraclelinux-6.7
Affected pkg:rpm/oraclelinux/nspr-devel?distro=oraclelinux-7.1 oraclelinux nspr-devel < 4.10.8-2.el7_1 oraclelinux-7.1
Affected pkg:rpm/oraclelinux/nspr-devel?distro=oraclelinux-6.7 oraclelinux nspr-devel < 4.10.8-2.el6_7 oraclelinux-6.7
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...