Vulnerability Bulletins

DSA-3998 nss - security update

   
Affected software Debian
 
Martin Thomson discovered that nss, the Mozilla Network Security Servicelibrary, is prone to a use-after-free vulnerability in the TLS 1.2implementation when handshake hashes are generated. A remote attackercan take advantage of this flaw to cause an application using the nsslibrary to crash, resulting in a denial of service, or potentially toexecute arbitrary code.

More info:

https://www.debian.org/security/2017/dsa-3998