Page 1 of 1

[SOLVED]Vulnerability-nss 3.72 critical-memory corruption

Posted: Sat Dec 04, 2021 6:13 pm
by Morty
Output from;

Code: Select all

sudo pkg audit -F
Fetching vuln.xml.xz: 100% 919 KiB 940.9kB/s 00:01
nss-3.72 is vulnerable:
NSS -- Memory corruption
CVE: CVE-2021-43527
WWW: https://vuxml.FreeBSD.org/freebsd/47695 ... 17024.html

1 problem(s) in 1 installed package(s) found.

Something i installed,perhaps? Installed 'fltk' from 'Software Station' yesterday. I think i might uninstall that.

Re: Vulnerability-nss 3.72 critical-memory corruption

Posted: Sat Dec 04, 2021 7:42 pm
by nevets
More detail...
NSS 3.72
Fixed in 3.73 at https://github.com/freebsd/freebsd-port ... curity/nss
Note: This vulnerability does NOT impact Mozilla Firefox.
However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted.
Steve

Re: Vulnerability-nss 3.72 critical-memory corruption

Posted: Sun Dec 05, 2021 8:52 am
by ericbsd
You should report the security issues on our GitHub issue. It is more easy to follow up.

Re: Vulnerability-nss 3.72 critical-memory corruption

Posted: Sun Dec 05, 2021 9:06 am
by ericbsd
I did start a build yesterday, and the update of NSS to 3.73 is coming.

Re: Vulnerability-nss 3.72 critical-memory corruption

Posted: Sun Dec 05, 2021 9:13 am
by Morty
ericbsd wrote: Sun Dec 05, 2021 8:52 am You should report the security issues on our GitHub issue. It is more easy to follow up.
I understand. Will do that from now on. Thank you for prompt response and being ahead of this issue for resolve. :)