Re: about CVE-2023-6125 in nss 3.42.1 in Debian Buster

"'Dana Keeler' via [email protected]" <[email protected]> Mon, 24 Jun 2024 09:25:15 -0700
Newsgroups gmane.comp.mozilla.crypto
Message-ID <CAHP1u2hfKbYu0kpteRtsyH5-iZBof=Lk9BChf6nJBFSsJUZvNQ@mail.gmail.com>
--0000000000008e5b03061ba53a02
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

To save others from potential confusion, the CVE in question is
CVE-2023-6135, not 6125.

On Sun, Jun 23, 2024 at 11:55=E2=80=AFPM Arturo Borrero Gonzalez <
[email protected]> wrote:

> Hi there,
>
> I am exploring how to fix CVE-2023-6125 in the nss package (version
> 3.42.1) in
> Debian Buster.
>
> There is a note from a Debian college saying that we should wait until yo=
u
> have
> backported the fix to the 3.90 series, but scanning your releases did not
> immediately showed to me where (if any) can I find a patch that I could
> cherry
> pick for 3.42.1.
>
> My college also tried to manually backport the published patches for nss
> Debian
> version 3.42.1, find them here:
>
> * part 1
>
> https://salsa.debian.org/lts-team/packages/nss/-/blob/debian/buster/debia=
n/patches/CVE-2023-6135-part1.patch?ref_type=3Dheads
> * part 2
>
> https://salsa.debian.org/lts-team/packages/nss/-/blob/debian/buster/debia=
n/patches/CVE-2023-6135-part2.patch?ref_type=3Dheads
>
> But I would like to be cautious before shipping them, given how sensitive
> the
> matter is.
>
> Do you have any advice on how to move forward with this?
>
> If the answer is 'forget about CVE-2023-6125 for such an older nss
> version',
> then I guess that's also a valid answer. Maybe I could try to backport an
> nss
> ESR version into older Debian versions, if you have any ESR version with
> CVE-2023-6125 fixed.
>
> thanks, regards.
>
> --
> You received this message because you are subscribed to the Google Groups=
 "
> [email protected]" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit
> https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/92cbadfa-=
0a9e-4f13-a096-0c7b2fe70d62%40gmail.com
> .
>

--=20
You received this message because you are subscribed to the Google Groups "=
[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to [email protected].
To view this discussion on the web visit https://groups.google.com/a/mozill=
a.org/d/msgid/dev-tech-crypto/CAHP1u2hfKbYu0kpteRtsyH5-iZBof%3DLk9BChf6nJBF=
SsJUZvNQ%40mail.gmail.com.

--0000000000008e5b03061ba53a02
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">To save others from potential confusion, the CVE in questi=
on is CVE-2023-6135, not 6125.</div><br><div class=3D"gmail_quote"><div dir=
=3D"ltr" class=3D"gmail_attr">On Sun, Jun 23, 2024 at 11:55=E2=80=AFPM Artu=
ro Borrero Gonzalez &lt;<a href=3D"mailto:[email protected]">ar=
[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gm=
ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,=
204,204);padding-left:1ex">Hi there,<br>
<br>
I am exploring how to fix CVE-2023-6125 in the nss package (version 3.42.1)=
 in <br>
Debian Buster.<br>
<br>
There is a note from a Debian college saying that we should wait until you =
have <br>
backported the fix to the 3.90 series, but scanning your releases did not <=
br>
immediately showed to me where (if any) can I find a patch that I could che=
rry <br>
pick for 3.42.1.<br>
<br>
My college also tried to manually backport the published patches for nss De=
bian <br>
version 3.42.1, find them here:<br>
<br>
* part 1 <br>
<a href=3D"https://salsa.debian.org/lts-team/packages/nss/-/blob/debian/bus=
ter/debian/patches/CVE-2023-6135-part1.patch?ref_type=3Dheads" rel=3D"noref=
errer" target=3D"_blank">https://salsa.debian.org/lts-team/packages/nss/-/b=
lob/debian/buster/debian/patches/CVE-2023-6135-part1.patch?ref_type=3Dheads=
</a><br>
* part 2 <br>
<a href=3D"https://salsa.debian.org/lts-team/packages/nss/-/blob/debian/bus=
ter/debian/patches/CVE-2023-6135-part2.patch?ref_type=3Dheads" rel=3D"noref=
errer" target=3D"_blank">https://salsa.debian.org/lts-team/packages/nss/-/b=
lob/debian/buster/debian/patches/CVE-2023-6135-part2.patch?ref_type=3Dheads=
</a><br>
<br>
But I would like to be cautious before shipping them, given how sensitive t=
he <br>
matter is.<br>
<br>
Do you have any advice on how to move forward with this?<br>
<br>
If the answer is &#39;forget about CVE-2023-6125 for such an older nss vers=
ion&#39;, <br>
then I guess that&#39;s also a valid answer. Maybe I could try to backport =
an nss <br>
ESR version into older Debian versions, if you have any ESR version with <b=
r>
CVE-2023-6125 fixed.<br>
<br>
thanks, regards.<br>
<br>
-- <br>
You received this message because you are subscribed to the Google Groups &=
quot;<a href=3D"mailto:[email protected]" target=3D"_blank">dev-t=
[email protected]</a>&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:dev-tech-crypto%[email protected]" target=
=3D"_blank">[email protected]</a>.<br>
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/mozilla.org/d/msgid/dev-tech-crypto/92cbadfa-0a9e-4f13-a096-0c7b2fe70d=
62%40gmail.com" rel=3D"noreferrer" target=3D"_blank">https://groups.google.=
com/a/mozilla.org/d/msgid/dev-tech-crypto/92cbadfa-0a9e-4f13-a096-0c7b2fe70=
d62%40gmail.com</a>.<br>
</blockquote></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;[email protected]&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">dev-tech=
[email protected]</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/mozilla.org/d/msgid/dev-tech-crypto/CAHP1u2hfKbYu0kpteRtsyH5-iZBof%3DL=
k9BChf6nJBFSsJUZvNQ%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter=
">https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/CAHP1u2hf=
KbYu0kpteRtsyH5-iZBof%3DLk9BChf6nJBFSsJUZvNQ%40mail.gmail.com</a>.<br />

--0000000000008e5b03061ba53a02--