Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1347908 - (CVE-2016-2834) CVE-2016-2834 nss: Multiple security flaws (MFSA 2016-61)
CVE-2016-2834 nss: Multiple security flaws (MFSA 2016-61)
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20160607,repor...
: Security
: 1380171 1380172 1380173 (view as bug list)
Depends On: 1383884 1383885 1383886 1383887 1383888 1416776
Blocks: 1343293 1380228
  Show dependency treegraph
 
Reported: 2016-06-18 04:40 EDT by Huzaifa S. Sidhpurwala
Modified: 2017-01-26 06:28 EST (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Multiple buffer handling flaws were found in the way NSS handled cryptographic data from the network. A remote attacker could use these flaws to crash an application using NSS or, possibly, execute arbitrary code with the permission of the user running the application.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-11-16 01:12:07 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
backported patch (7.94 KB, patch)
2016-10-13 12:15 EDT, Kai Engert (:kaie) (inactive account)
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:2779 normal SHIPPED_LIVE Moderate: nss and nss-util security update 2016-11-22 08:49:09 EST

  None (edit)
Description Huzaifa S. Sidhpurwala 2016-06-18 04:40:05 EDT
Mozilla has updated the version of Network Security Services (NSS) library used in Firefox to NSS 3.23. This addresses four moderate rated networking security issues reported by Mozilla engineers Tyson Smith and Jed Davis. 


External Reference:

https://www.mozilla.org/security/announce/2016/mfsa2016-61.html


Acknowledgements:

Name: the Mozilla project
Upstream: Tyson Smith and Jed Davis
Comment 3 Huzaifa S. Sidhpurwala 2016-06-18 04:48:39 EDT
These security flaws were fixed in nss-3.23

Fedora 22 and Fedora 23 already contains nss-3.24 and therefore is not affected by these flaws.
Comment 4 Huzaifa S. Sidhpurwala 2016-10-02 22:55:17 EDT
Mitigation:

Do not use NSS to parse untrusted certificates.
Comment 9 Kai Engert (:kaie) (inactive account) 2016-10-13 12:14:51 EDT
(In reply to Huzaifa S. Sidhpurwala from comment #2)
> This flaw corresponds to the following upstream commits:
> 
> https://hg.mozilla.org/projects/nss/rev/8d78a5ae260a
> https://hg.mozilla.org/projects/nss/rev/1ba7cd83c672
> https://hg.mozilla.org/projects/nss/rev/5fde729fdbff
> https://hg.mozilla.org/projects/nss/rev/329932eb1700

The patches apply cleanly on top of each other in the following order:
https://hg.mozilla.org/projects/nss/rev/8d78a5ae260a
https://hg.mozilla.org/projects/nss/rev/5fde729fdbff
https://hg.mozilla.org/projects/nss/rev/1ba7cd83c672
https://hg.mozilla.org/projects/nss/rev/329932eb1700

I recommend to add the following very minor change, which only affects test code, but was made before the above changes, so including it makes sense for completeness:
https://hg.mozilla.org/projects/nss/rev/b6bcbd62e833

I have merged all those changes into a single patch, which I'm attaching to the bug.

The patches seem isolated, without references to other code. Backporting should be safe.
Comment 10 Kai Engert (:kaie) (inactive account) 2016-10-13 12:15 EDT
Created attachment 1210200 [details]
backported patch
Comment 11 Kai Engert (:kaie) (inactive account) 2016-10-13 12:29:52 EDT
*** Bug 1380171 has been marked as a duplicate of this bug. ***
Comment 12 Kai Engert (:kaie) (inactive account) 2016-10-13 12:29:55 EDT
*** Bug 1380172 has been marked as a duplicate of this bug. ***
Comment 13 Kai Engert (:kaie) (inactive account) 2016-10-13 12:29:56 EDT
*** Bug 1380173 has been marked as a duplicate of this bug. ***
Comment 15 errata-xmlrpc 2016-11-16 00:59:02 EST
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 7
  Red Hat Enterprise Linux 5

Via RHSA-2016:2779 https://rhn.redhat.com/errata/RHSA-2016-2779.html

Note You need to log in before you can comment on or make changes to this bug.