← Search the atlas
SUSE-SU-2020:0088-1
Not scored
Security update for mozilla-nspr, mozilla-nss
This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to NSS 3.47.1:
Security issues fixed:
- CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819).
- CVE-2019-11745: EncryptUpdate should use maxout, not block size (bsc#1158527).
- CVE-2019-11727: Fixed vulnerability sign CertificateVerify with PKCS#1 v1.5 signatures issue (bsc#1141322).
mozilla-nspr was updated to version 4.23:
- Whitespace in C files was cleaned up and no longer uses tab characters for indenting.
Exploit probability
Not scored
Published
January 13, 2020
Required by
Not available
Last source change
May 2, 2025
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Linux Enterprise Server 12 SP2-LTSS
mozilla-nss
SUSE:Linux Enterprise Server for SAP Applications 12 SP1
mozilla-nspr
SUSE:Linux Enterprise Server for SAP Applications 12 SP5
mozilla-nspr
SUSE:Linux Enterprise Server 12 SP3-BCL
mozilla-nspr
SUSE:HPE Helion OpenStack 8
mozilla-nss
SUSE:Linux Enterprise Server 12 SP4
mozilla-nss
SUSE:Linux Enterprise Server 12 SP2-BCL
mozilla-nss
SUSE:Linux Enterprise Server for SAP Applications 12 SP4
mozilla-nspr
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
mozilla-nss
SUSE:OpenStack Cloud 8
mozilla-nspr
SUSE:Linux Enterprise Server 12 SP1-LTSS
mozilla-nspr
SUSE:Linux Enterprise Software Development Kit 12 SP5
mozilla-nspr
SUSE:OpenStack Cloud Crowbar 8
mozilla-nspr
SUSE:Linux Enterprise Server for SAP Applications 12 SP5
mozilla-nss
SUSE:Linux Enterprise Server for SAP Applications 12 SP4
mozilla-nss
SUSE:Linux Enterprise Software Development Kit 12 SP4
mozilla-nss
SUSE:Linux Enterprise Server 12 SP2-BCL
mozilla-nspr
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
mozilla-nspr
SUSE:Enterprise Storage 5
mozilla-nss
SUSE:HPE Helion OpenStack 8
mozilla-nspr
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
mozilla-nspr
SUSE:Linux Enterprise Desktop 12 SP4
mozilla-nspr
SUSE:Linux Enterprise Server 12 SP3-BCL
mozilla-nss
SUSE:Linux Enterprise Server 12 SP5
mozilla-nss
SUSE:Linux Enterprise Server 12 SP5
mozilla-nspr
SUSE:Linux Enterprise Server 12 SP2-LTSS
mozilla-nspr
SUSE:OpenStack Cloud Crowbar 8
mozilla-nss
SUSE:Linux Enterprise Server 12 SP1-LTSS
mozilla-nss
SUSE:Linux Enterprise Desktop 12 SP4
mozilla-nss
SUSE:Linux Enterprise Server 12 SP3-LTSS
mozilla-nss
SUSE:OpenStack Cloud 7
mozilla-nss
SUSE:Linux Enterprise Server 12 SP3-LTSS
mozilla-nspr
SUSE:Linux Enterprise Server 12 SP4
mozilla-nspr
SUSE:Linux Enterprise Software Development Kit 12 SP5
mozilla-nss
SUSE:OpenStack Cloud 7
mozilla-nspr
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
mozilla-nss
SUSE:Linux Enterprise Server for SAP Applications 12 SP1
mozilla-nss
SUSE:Linux Enterprise Software Development Kit 12 SP4
mozilla-nspr
SUSE:OpenStack Cloud 8
mozilla-nss
SUSE:Enterprise Storage 5
mozilla-nspr
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2020:0088-1
This update for mozilla-nspr, mozilla-nss fixes the following issues:
mozilla-nss was updated to NSS 3.47.1:
Security issues fixed:
- CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819).
- CVE-2019-11745: EncryptUpdate should use maxout, not block size (bsc#1158527).
- CVE-2019-11727: Fixed vulnerability sign CertificateVerify with PKCS#1 v1.5 signatures issue (bsc#1141322).
mozilla-nspr was updated to version 4.23:
- Whitespace in C files was cleaned up and no longer uses tab characters for indenting.
View original source ↗
05 / REFERENCES
Further evidence