USN-927-2: NSS regression


 
Thread Tools Search this Thread
Special Forums Cybersecurity Security Advisories (RSS) USN-927-2: NSS regression
# 1  
Old 04-11-2010
USN-927-2: NSS regression

Description:
===========================================================Ubuntu Security Notice USN-927-2 April 11, 2010nss regressionhttps://launchpad.net/bugs/559881===========================================================A security issue affects the following Ubuntu releases:Ubuntu 9.10This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 9.10: libnss3-1d 3.12.6-0ubuntu0.9.10.2After a standard system upgrade you need to restart your session to effectthe necessary changes.Details follow:USN-927-1 fixed vulnerabilities in NSS. Upstream NSS 3.12.6 added anadditional checksum verification on libnssdbm3.so, but the Ubuntu packagingdid not create this checksum. As a result, Firefox could not initialize thesecurity component when the NSS Internal FIPS PKCS #11 Module was enabled.This update fixes the problem.We apologize for the inconvenience.Original advisory details: Marsh Ray and Steve Dispensa discovered a flaw in the TLS and SSLv3 protocols. If an attacker could perform a man in the middle attack at the start of a TLS connection, the attacker could inject arbitrary content at the beginning of the user's session. This update adds support for the new new renegotiation extension and will use it when the server supports it.





More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
DC1394_VLOOPBACK(1)						   User Commands					       DC1394_VLOOPBACK(1)

NAME
dc1394_vloopback - send format0 video to V4L vloopback device SYNOPSIS
dc1394_vloopback [--daemon] [--pipe] [--guid=camera-euid] [--video1394=/dev/video1394/x] [--vloopback=/dev/video0] [--palette=yuv422|rgb24] [--width=n] [--height=n] DESCRIPTION
Sends format0 640x480 RGB to the vloopback input device so that it can be consumed by V4L applications on the vloopback output device. OPTIONS
--daemon run as a daemon, detached from console (optional). --pipe write images to vloopback device instead of using zero-copy mmap mode (optional). --guid select camera to use (optional). default is first camera on any port. --video1394 specifies video1394 device to use (optional). default is /dev/video1394/<port#>. --vloopback specifies video4linux device to use (optional). default is to determine this automatically. --palette specify the video palette to use (optional). yuv422 (default) or rgb24. --width set the initial width (default=640) --height set the initial height (default=480) --help print help message BUGS
This program is maintained by the DC1394 Package Mainteners' team <libdc1394-packaging@lists.sourceforge.net>. The bugs related to libdc1394 and current packaging can be submitted here: http://bugs.launchpad.net/~libdc1394-dev/ For bugs related to library implementation, please submit to libdc1394 developers: <libdc1394-dev@lists.sourceforge.net>. AUTHOR
This manual page was originally written by Peter De Schrijver <p2@debian.org> for the Debian GNU/Linux system (but may be used by others). COPYRIGHT
This manual page is maintained by the DC1394 Package Mainteners' team. The team members and other information can be found online at: http://launchpad.net/~libdc1394-dev Permission is granted to copy, distribute and/or modify this document under the terms of the GNU General Public License, Version 3 or any later version published by the Free Software Foundation. On Debian systems (like Ubuntu), the complete text of the GNU General Public License can be found in /usr/share/common-licenses/GPL-3. SEE ALSO
dc1394_reset_bus(1) dc1394_vloopback February 2008 DC1394_VLOOPBACK(1)