SB2016032406 - Input validation error in nss (Alpine package)
Published: March 24, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2016-1979)
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=1968c4c07185a7285a798c7a5d0aaf78abeadea7
- https://git.alpinelinux.org/aports/commit/?id=b72b361c8512d6026da87313218e7b2f4459e0ff
- https://git.alpinelinux.org/aports/commit/?id=59192f802c63d7a2d7d3e16cc28e04f6438f50cb
- https://git.alpinelinux.org/aports/commit/?id=cc3e00e4e5cc5c47d52db2a744cd41f1cefaa761