ELA-194-1 nss security update

out-of-bounds write

2019-11-25
Packagenss
Version2:3.26-1+debu7u9
Related CVEs CVE-2019-11745


A vulnerability has been discovered in nss, the Mozilla Network Security Service library. An out-of-bounds write can occur when passing an output buffer smaller than the block size to NSC_EncryptUpdate.



For Debian 7 Wheezy, these problems have been fixed in version 2:3.26-1+debu7u9.

We recommend that you upgrade your nss packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.