about CVE-2024-6609 for nss 3.61 in Debian Bullseye

Arturo Borrero Gonzalez <[email protected]> Wed, 25 Sep 2024 13:02:51 -0700 (PDT)
Newsgroups gmane.comp.mozilla.crypto
Message-ID <[email protected]>
------=_Part_205738_190428022.1727294571228
Content-Type: multipart/alternative; 
	boundary="----=_Part_205739_1360410101.1727294571228"

------=_Part_205739_1360410101.1727294571228
Content-Type: text/plain; charset="UTF-8"

Hi there,

I'm interested in having a patch for CVE-2024-6609 available for the nss 
version we have in Debian Bullseye (nss 3.61).

We have a note [0] that mentions this:

=== 8< ===
To address CVE in older versions of src:nss what is needed is to add the 
error
handling code (confirmed by upstream):
https://searchfox.org/nss/rev/ba9330537e6e94971de8b9bc49460891b23afd4f/lib/freebl/ec.c#379-382
to the ec_NewKey function, in the cleanup section, after mp_clear and
before `if (rv)`.
=== 8< ===

I was hoping that you could provide this patch yourself, because I don't 
think just a copy/paste (like the note seems to suggest), would be enough.

Please, let me know if you can help with this.

thanks, regards.

[0] https://security-tracker.debian.org/tracker/CVE-2024-6609


-- 
You received this message because you are subscribed to the Google Groups "[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/66071e21-a687-49f2-a709-5244a06438b6n%40mozilla.org.

------=_Part_205739_1360410101.1727294571228
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div>Hi there,</div><div><br /></div><div>I'm interested in having a patch =
for CVE-2024-6609 available for the nss version we have in Debian Bullseye =
(nss 3.61).</div><div><br /></div><div>We have a note [0] that mentions thi=
s:</div><div><br /></div><div>=3D=3D=3D 8&lt; =3D=3D=3D<br /></div><div><sp=
an><span>To address CVE in older versions of src:nss what is needed is to a=
dd the error</span><br /><span>handling code (confirmed by upstream):</span=
><br /><a href=3D"https://searchfox.org/nss/rev/ba9330537e6e94971de8b9bc494=
60891b23afd4f/lib/freebl/ec.c#379-382">https://searchfox.org/nss/rev/ba9330=
537e6e94971de8b9bc49460891b23afd4f/lib/freebl/ec.c#379-382</a><br /><span>t=
o the ec_NewKey function, in the cleanup section, after mp_clear and</span>=
<br /><span>before `if (rv)`.</span></span></div><div>=3D=3D=3D 8&lt; =3D=
=3D=3D</div><div><br /></div><div>I was hoping that you could provide this =
patch yourself, because I don't think just a copy/paste (like the note seem=
s to suggest), would be enough.</div><div><br /></div><div>Please, let me k=
now if you can help with this.</div><div><br /></div><div>thanks, regards.<=
br /></div><div><br /></div><div>[0] https://security-tracker.debian.org/tr=
acker/CVE-2024-6609</div><div><br /></div><div><br /></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;[email protected]&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">dev-tech=
[email protected]</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/mozilla.org/d/msgid/dev-tech-crypto/66071e21-a687-49f2-a709-5244a06438=
b6n%40mozilla.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.go=
ogle.com/a/mozilla.org/d/msgid/dev-tech-crypto/66071e21-a687-49f2-a709-5244=
a06438b6n%40mozilla.org</a>.<br />

------=_Part_205739_1360410101.1727294571228--

------=_Part_205738_190428022.1727294571228--