Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.123876
Category:Oracle Linux Local Security Checks
Title:Oracle: Security Advisory (ELSA-2012-0973)
Summary:The remote host is missing an update for the 'nspr, nss, nss-util' package(s) announced via the ELSA-2012-0973 advisory.
Description:Summary:
The remote host is missing an update for the 'nspr, nss, nss-util' package(s) announced via the ELSA-2012-0973 advisory.

Vulnerability Insight:
nspr
[4.9-1]
- Resolves: rhbz#799193 - Update to 4.9

nss
[3.13.3-6.0.1.el6]
- Added nss-vendor.patch to change vendor
- Use blank image instead of clean.gif in tar ball

[3.13.3-6]
- Resolves: #rhbz#805232 PEM module may attempt to free uninitialized pointer

[3.13.3-5]
- Resolves: rhbz#717913 - [PEM] various flaws detected by Coverity
- Require nss-util 3.13.3

[3.13.3-4]
- Resolves: rhbz#772628 nss_Init leaks memory

[3.13.3-3]
- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name
- Use completed patch per code review

[3.13.3-2]
- Resolves: rhbz#746632 - pem_CreateObject mem leak on non existing file name
- Resolves: rhbz#768669 - PEM unregistered callback causes SIGSEGV

[3.13.3-1]
- Update to 3.13.3
- Resolves: rhbz#798539 - Distrust MITM subCAs issued by TrustWave
- Remove builtins-nssckbi_1_88_rtm.patch which the rebase obsoletes

nss-util
[3.13.3-2]
- Resolves: rhbz#799192 - Update to 3.13.3
- Update minimum nspr version for Requires and BuildRequires to 4.9
- Fix version/release in changelog to match the Version and Release tags, now 3.13.3-2

[3.13.1-5]
- Resolves: rhbz#799192 - Update to 3.13.3

Affected Software/OS:
'nspr, nss, nss-util' package(s) on Oracle Linux 6.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.