Re: Analysis of nss CVE-2016-2834

2016-06-18 Thread Guido Günther
Hi Ola, On Sat, Jun 18, 2016 at 12:15:15AM +0200, Ola Lundqvist wrote: [..snip..] > So I have now gone through the ~7 MB diff between nss and found changes > regarding the following: > - ASN1 parsing issue. See also CVE-2016-1950 > - A lot of changes from getenv to some secure variant. > - A change

Analysis of nss CVE-2016-2834

2016-06-17 Thread Ola Lundqvist
Hi LTS Team I have gone through what I can find about CVE-2016-2834 listed in the security tracker for nss. The most interesting information can be found here: https://www.mozilla.org/en-US/security/advisories/mfsa2016-61/ "Mozilla has updated the version of Network Security Services (NSS) librar