Sicherheit: Mehrere Probleme in nspr
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in nspr
ID: FEDORA-2011-17399
Distribution: Fedora
Plattformen: Fedora 15
Datum: So, 22. Januar 2012, 12:42
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3389
Applikationen: nspr


Name        : nspr
Product : Fedora 15
Version : 4.8.9
Release : 2.fc15
URL : http://www.mozilla.org/projects/nspr/
Summary : Netscape Portable Runtime
Description :
NSPR provides platform independence for non-GUI operating system
facilities. These facilities include threads, thread synchronization,
normal file and network I/O, interval timing and calendar time, basic
memory management (malloc and free) and shared library linking.

Update Information:

The latest version of Firefox and Thunderbird have the following changes:

* Added Type Inference, significantly improving JavaScript performance
* Added support for querying Do Not Track status via JavaScript
* Added support for font-stretch
* Improved support for text-overflow
* Improved standards support for HTML5, MathML, and CSS
* Fixed several stability issues
* Fixed several security issues

Notable nss changes include:

1. SSL 2.0 is disabled by default.

2. A defense against the SSL 3.0 and TLS 1.0 CBC chosen plaintext attack
demonstrated by Rizzo and Duong (CVE-2011-3389) is enabled by default.
Set the SSL_CBC_RANDOM_IV SSL option to PR_FALSE to disable it.

3. SHA-224 is supported.

4. Added PORT_ErrorToString and PORT_ErrorToName to return the
error message and symbolic name of an NSS error code.

5. Added NSS_GetVersion to return the NSS version string.

6. Added experimental support of RSA-PSS to the softoken only
(contributed by Hanno Böck, http://rsapss.hboeck.de/).


* Thu Sep 8 2011 Ville Skyttä <ville.skytta@iki.fi> - 4.8.9-2
- Avoid %post/un shell invocations and dependencies.
* Tue Aug 9 2011 Elio Maldonado <emaldona@redhat.com> - 4.8.9-1
- Update to NSPR_4_8_9_RTM
* Mon Jul 18 2011 Elio Maldonado <emaldona@redhat.com> - 4.8.8-4
- The tests must pass for the build to succeed
* Mon Jul 18 2011 Elio Maldonado <emaldona@redhat.com> - 4.8.8-3
- Run the nspr test suite in the %check section
* Wed Jul 6 2011 Elio Maldonado <emaldona@redhat.com> - 4.8.8-2
- Conditionalize Thumb2 build support on right Arm arches
* Fri May 6 2011 Elio Maldonado <emaldona@redhat.com> - 4.8.8-1
- Update to NSPR_4_8_8_RTM
* Mon Apr 25 2011 Elio Maldonado Batiz <emaldona@redhat.com> -
- Update to NSPR_4_8_8_BETA3

This update can be installed with the "yum" update program. Use
su -c 'yum update nspr' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Neue Nachrichten