aboutsummaryrefslogtreecommitdiffstats
path: root/english/lts/security/2016/dla-676.wml
blob: f8d40aec79f637b4c07cb921b3733b87dfe3e55c (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
<define-tag description>LTS security update</define-tag>
<define-tag moreinfo>
<p>The Network Security Service (NSS) libraries uses
environment variables to configure lots of things, some of which refer to
file system locations. Others can be degrade the operation of NSS in various
ways, forcing compatibility modes and so on.</p>

<p>Previously, these environment variables were not ignored SUID
binaries. This version of NetScape Portable Runtime Library (NSPR)
introduce a new API, PR_GetEnVSecure, to address this.</p>

<p>Both NSPR and NSS need to be upgraded to address this problem.</p>

<p>For Debian 7 <q>Wheezy</q>, these problems have been fixed in NSPR version
4.12-1+deb7u1.</p>

<p>We recommend that you upgrade your nspr packages.</p>

<p>Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: <a href="https://wiki.debian.org/LTS">https://wiki.debian.org/LTS</a></p>
</define-tag>

# do not modify the following line
#include "$(ENGLISHDIR)/lts/security/2016/dla-676.data"
# $Id: $

© 2014-2024 Faster IT GmbH | imprint | privacy policy