ELA-194-1 nss security update

out-of-bounds write

2019-11-25
Packagenss
Version2:3.26-1+debu7u9
Related CVE CVE-2019-11745

A vulnerability has been discovered in nss, the Mozilla Network Security Service library. An out-of-bounds write can occur when passing an output buffer smaller than the block size to NSC_EncryptUpdate.

For Debian 7 Wheezy, these problems have been fixed in version 2:3.26-1+debu7u9.

We recommend that you upgrade your nss packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/