LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 01-25-2014, 04:21 AM   #1
gengisdave
Member
 
Registered: Dec 2013
Location: Turin, Italy
Distribution: slackware
Posts: 328

Rep: Reputation: 74
Mozilla-NSS vulnerability (CVE-2013-1740)


I've read this, version 3.15.4 is slightly different, nspr is shipped with nss, no more as a standalone source, the slackbuild needs a little changes

and now something complet... and now a question:

i've seen nspr is linked with the running kernel, i've compiled it on the desktop pc with 3.10 (standard 14.1 kernel), but my laptop, who share the packages has 3.13, there will be some kind of problems?
 
Old 01-28-2014, 10:28 AM   #2
55020
Senior Member
 
Registered: Sep 2009
Location: Yorks. W.R. 167397
Distribution: Slackware
Posts: 1,307
Blog Entries: 4

Rep: Reputation: Disabled
Quote:
Originally Posted by gengisdave View Post
i've seen nspr is linked with the running kernel,
o_O

Uh, no. (The "kernel headers" in /usr/include/linux don't count - those are platform-specific headers for linking with glibc, *not* for linking with the running kernel. The kernel does not ship any .so libraries.)

Quote:
Originally Posted by gengisdave View Post
i've compiled it on the desktop pc with 3.10 (standard 14.1 kernel), but my laptop, who share the packages has 3.13, there will be some kind of problems?
I have linux-3.13.0 running with slackware-14.1 here, and libnspr4.so from seamonkey-solibs-2.23-x86_64-1_slack14.1 works fine for me -- presumably Patrick compiled that on 3.10.17, so it's exactly the same situation.

In general, the only stuff that links with the kernel (and needs recompiling for a new kernel) is stuff that installs its own kernel modules in /lib/modules/<version> (eg. nvidia, virtualbox).

Patrick is usually quite assiduous about security updates for openssl and seamonkey-solibs, so it's possible that this will see an official Slackware patch soon.
 
Old 01-28-2014, 01:29 PM   #3
mancha
Member
 
Registered: Aug 2012
Posts: 484

Rep: Reputation: Disabled
Firefox, SeaMonkey, and Thunderbird, as currently shipped in Slackware 14.1, are unaffected as long as security.ssl.enable_false_start is not changed from its default value of false.

Those interested/worried can verify this setting in about:config (Firefox & SeaMonkey) or the config editor (Thunderbird).

I believe the only other stock Slackware application that uses libssl3 for SSL/TLS transport is Pidgin. It's also unaffected because it doesn't make use of abbreviated handshakes. If there is another stock Slackware program I've missed let me know.

Nonetheless, it would be good to upgrade to NSS 3.15.4 in case other clients link libssl3 with false start enabled.

--mancha

Last edited by mancha; 01-28-2014 at 09:17 PM.
 
Old 01-28-2014, 09:19 PM   #4
mancha
Member
 
Registered: Aug 2012
Posts: 484

Rep: Reputation: Disabled
For those wondering why OP marked this solved:

Tue Jan 28 21:07:13 UTC 2014
l/mozilla-nss-3.15.4-i486-1.txz: Upgraded.
Upgraded to nss-3.15.4 and nspr-4.10.3.
Fixes a possible man-in-the-middle issue.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename...=CVE-2013-1740
(* Security fix *)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Ubuntu: 2088-1: NSS vulnerability LXer Syndicated Linux News 0 01-25-2014 02:40 AM
US Cert: TA14-013A: NTP Amplification Attacks Using CVE-2013-5211 tronayne Slackware 7 01-15-2014 12:35 PM
[SOLVED] [Slackware-current]: glibc 2.17; CVE-2013-4332 mancha Slackware 12 11-11-2013 03:08 PM
X.org security advisory CVE-2013-4396 qunying Slackware 1 10-09-2013 09:32 PM
Patch of vulnerability CVE:2007-5001 nnetala Linux - Newbie 0 06-26-2008 03:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 05:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration