RHSA-2023:1406: Important: nss security update
Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications.Security Fix(es): nss: Arbitrary memory write via PKCS 12 (CVE-2023-0767) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nssto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-debuginfoto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-debugsourceto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-develto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-softoknto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-softokn-debuginfoto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-softokn-develto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-softokn-freeblto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-softokn-freebl-debuginfoto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-softokn-freebl-develto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-sysinitto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-sysinit-debuginfoto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-toolsto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-tools-debuginfoto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-utilto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-util-debuginfoto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
redhat/nss-util-develto a version that resolves this vulnerability.Fixed in 3.53.1-13.el8_2 - Upgrade
Upgrade
nssto a version that resolves this vulnerability.Fixed in nss-3.53.1-13.el8_2.x86_64.rpm - Upgrade
Upgrade
nssto a version that resolves this vulnerability.Fixed in nss-3.53.1-13.el8_2.ppc64le.rpm - Upgrade
Upgrade
nssto a version that resolves this vulnerability.Fixed in nss-3.53.1-13.el8_2.i686.rpm
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:1406?
The severity of RHSA-2023:1406 is classified as important.
How do I fix RHSA-2023:1406?
To fix RHSA-2023:1406, update the affected packages to version 3.53.1-13.el8_2.
What vulnerability is addressed in RHSA-2023:1406?
RHSA-2023:1406 addresses an arbitrary memory write vulnerability via PKCS 12, identified as CVE-2023-0767.
Which software packages are affected by RHSA-2023:1406?
Affected packages include nss, nss-debuginfo, nss-devel, and several others specified in the advisory.
When was RHSA-2023:1406 released?
RHSA-2023:1406 was released to address security vulnerabilities in Network Security Services.