RedHat has issued an advisory today (May 30): https://rhn.redhat.com/errata/RHSA-2017-1365.html I have updated to 3.28.5 in SVN, which just fixes one bug (the rootcerts changes have already been pushed), and added the patch for the security issue. Advisory will be as follows. Advisory: ======================== Updated nss packages fix security vulnerability: A null pointer dereference flaw was found in the way NSS handled empty SSLv2 messages. An attacker could use this flaw to crash a server application compiled against the NSS library (CVE-2017-7502). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7502 https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.28.5_release_notes https://rhn.redhat.com/errata/RHSA-2017-1365.html ======================== Updated packages in core/updates_testing: ======================== nss-3.28.5-1.mga5 nss-doc-3.28.5-1.mga5 libnss3-3.28.5-1.mga5 libnss-devel-3.28.5-1.mga5 libnss-static-devel-3.28.5-1.mga5 from nss-3.28.5-1.mga5.src.rpm
Updated and patched packages uploaded for Mageia 5 and Cauldron. Advisory and package list in Comment 0.
Assignee: bugsquad => qa-bugs
Linux localhost 4.4.68-desktop-1.mga5 #1 SMP Sun May 14 17:56:12 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux The following 4 packages are going to be installed: - lib64nspr-devel-4.14-1.mga5.x86_64 - lib64nss-devel-3.28.5-1.mga5.x86_64 - lib64nss3-3.28.5-1.mga5.x86_64 - nss-3.28.5-1.mga5.x86_64 1.4MB of additional disk space will be used. 3.8MB of packages will be retrieved. Is it ok to continue? I am guessing here, but Redhat noted Firefox uses it so I installed the above and rebooted my machine to clear any cache. Started Firefox and from Firefox using SSH into cloud-server. That seems to be working as designed. Also https to mail servers, etc. All working equivalent.
Whiteboard: (none) => mga5-64-okCC: (none) => brtians1
Similar testing on Mageia 5 i586 ok. Advisory committed to svn. Validating.
Whiteboard: mga5-64-ok => mga5-64-ok advisory mga5-43-okKeywords: (none) => validated_updateCC: (none) => davidwhodgins, sysadmin-bugs
Whiteboard: mga5-64-ok advisory mga5-43-ok => mga5-64-ok advisory mga5-32-ok
An update for this issue has been pushed to the Mageia Updates repository. http://advisories.mageia.org/MGASA-2017-0160.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED