Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.122933
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2016-0685)
Summary:The remote host is missing an update for the 'nspr, nss, nss-softokn, nss-util' package(s) announced via the ELSA-2016-0685 advisory.
Description:Summary:
The remote host is missing an update for the 'nspr, nss, nss-softokn, nss-util' package(s) announced via the ELSA-2016-0685 advisory.

Vulnerability Insight:
nspr
[4.11.0-1]
- Rebase to NSPR 4.11

nss
[3.21.0-9.0.1]
- Added nss-vendor.patch to change vendor

[3.21.0-9]
- Rebuild to require the latest nss-util build and nss-softokn build.

[3.21.0-8]
- Update the minimum nss-softokn build required at runtime.

[3.21.0-7]
- Delete duplicates from one table

[3.21.0-6]
- Fix missing support for sha384/dsa in certificate_request

[3.21.0-5]
- Fix the SigAlgs sent in certificate_request

[3.21.0-4]
- Ensure all ssl.sh tests are executed
- Update sslauth test patch to run additional tests

[3.21.0-2]
- Fix sha384 support and testing patches

[3.21.0-1]
- Rebase to NSS-3.21
- Resolves: Bug 1310581

nss-softokn
[3.16.2.3-14.2]
- Adjust for a renamed variable in newer nss-util, require a compatible nss-util version.

[3.16.2.3-14.1]
- Pick up a bugfix related to fork(), to avoid a regression with NSS 3.21

[3.16.2.3-14]
- Pick up upstream freebl patch for CVE-2015-2730
- Check for P == Q or P ==-Q before adding P and Q

nss-util
[3.21.0-2.2]
- Rebase to nss-util from nss 3.21
- Add aliases for naming compatibility with prior release

Affected Software/OS:
'nspr, nss, nss-softokn, nss-util' package(s) on Oracle Linux 7.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-1978
BugTraq ID: 84275
http://www.securityfocus.com/bid/84275
BugTraq ID: 91787
http://www.securityfocus.com/bid/91787
Debian Security Information: DSA-3688 (Google Search)
http://www.debian.org/security/2016/dsa-3688
https://security.gentoo.org/glsa/201605-06
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21_release_notes
RedHat Security Advisories: RHSA-2016:0591
http://rhn.redhat.com/errata/RHSA-2016-0591.html
RedHat Security Advisories: RHSA-2016:0684
http://rhn.redhat.com/errata/RHSA-2016-0684.html
RedHat Security Advisories: RHSA-2016:0685
http://rhn.redhat.com/errata/RHSA-2016-0685.html
http://www.securitytracker.com/id/1035258
SuSE Security Announcement: SUSE-SU-2016:0727 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00027.html
SuSE Security Announcement: SUSE-SU-2016:0777 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00050.html
SuSE Security Announcement: SUSE-SU-2016:0820 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00068.html
SuSE Security Announcement: SUSE-SU-2016:0909 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00093.html
http://www.ubuntu.com/usn/USN-2973-1
Common Vulnerability Exposure (CVE) ID: CVE-2016-1979
BugTraq ID: 84221
http://www.securityfocus.com/bid/84221
Debian Security Information: DSA-3576 (Google Search)
http://www.debian.org/security/2016/dsa-3576
https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.21.1_release_notes
http://www.securitytracker.com/id/1035215
SuSE Security Announcement: openSUSE-SU-2016:0731 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00029.html
SuSE Security Announcement: openSUSE-SU-2016:0733 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00031.html
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.