ELEA-2017-0671

ELEA-2017-0671 - nspr and nss bug fix update

Type:ENHANCEMENT
Severity:NA
Release Date:2017-03-27

Description


nspr
[4.13.1-1]
- Rebase to NSPR 4.13.1

[4.13.0-1]
- Rebase to NSPR 4.13

[4.11.0-1]
- Rebase to NSPR 4.11
- Resolves: Bug 1297891 - Rebase RHEL 6.8 to NSPR 4.11 in preparation for Firefox 45

nss
[3.27.1-13.0.1]
- Added nss-vendor.patch to change vendor
- Temporarily disable some tests until expired PayPalEE.cert is renewed

[3.27.1-13]
- Update expired PayPalEE.cert

[3.27.1-12]
- Disable unsupported test cases in ssl_gtests

[3.27.1-11]
- Adjust the sslstress.txt filename so that it matches with the
disableSSL2tests patch ported from RHEL 7
- Exclude SHA384 and CHACHA20_POLY1305 ciphersuites from stress tests
- Don't add gtests and ssl_gtests to nss_tests, unless gtests are enabled

[3.27.1-10]
- Add patch to fix SSL CA name leaks, taken from NSS 3.27.2 release
- Add patch to fix bash syntax error in tests/ssl.sh
- Add patch to remove duplicate ciphersuites entries in sslinfo.c
- Add patch to abort selfserv/strsclnt/tstclnt on non-parsable version range
- Build with support for SSLKEYLOGFILE

[3.27.1-9]
- Update fix_multiple_open patch to fix regression in openldap client
- Remove pk11_genobj_leak patch, which caused crash with Firefox
- Add comment in the policy file to preserve the last empty line
- Disable SHA384 ciphersuites when CKM_TLS12_KEY_AND_MAC_DERIVE is not
provided by softoken; this superseds check_hash_impl patch

[3.27.1-8]
- Fix problem in check_hash_impl patch

[3.27.1-7]
- Add patch to check if hash algorithms are backed by a token
- Add patch to disable TLS_ECDHE_{RSA,ECDSA}_WITH_AES_128_CBC_SHA256,
which have never enabled in the past

[3.27.1-6]
- Add upstream patch to fix a crash. Mozilla #1315936

[3.27.1-5]
- Disable the use of RSA-PSS with SSL/TLS. #1390161

[3.27.1-4]
- Use updated upstream patch for RH bug 1387811

nss-util
[3.27.1-3]
- Tolerate policy file without last empty line

[3.27.1-2]
- Add missing source files

[3.27.1-1]
- Rebase to NSS 3.26.0
- Remove upstreamed patch for CVE-2016-1950
- Remove p-disable-md5-590364-reversed.patch for bug 1335915




Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete