about CVE-2024-6609 for nss 3.61 in Debian Bullseye
Arturo Borrero Gonzalez <[email protected]> Wed, 25 Sep 2024 13:02:51 -0700 (PDT)
| Newsgroups | gmane.comp.mozilla.crypto |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_205738_190428022.1727294571228 Content-Type: multipart/alternative; boundary="----=_Part_205739_1360410101.1727294571228" ------=_Part_205739_1360410101.1727294571228 Content-Type: text/plain; charset="UTF-8" Hi there, I'm interested in having a patch for CVE-2024-6609 available for the nss version we have in Debian Bullseye (nss 3.61). We have a note [0] that mentions this: === 8< === To address CVE in older versions of src:nss what is needed is to add the error handling code (confirmed by upstream): https://searchfox.org/nss/rev/ba9330537e6e94971de8b9bc49460891b23afd4f/lib/freebl/ec.c#379-382 to the ec_NewKey function, in the cleanup section, after mp_clear and before `if (rv)`. === 8< === I was hoping that you could provide this patch yourself, because I don't think just a copy/paste (like the note seems to suggest), would be enough. Please, let me know if you can help with this. thanks, regards. [0] https://security-tracker.debian.org/tracker/CVE-2024-6609 -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/66071e21-a687-49f2-a709-5244a06438b6n%40mozilla.org. ------=_Part_205739_1360410101.1727294571228 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div>Hi there,</div><div><br /></div><div>I'm interested in having a patch = for CVE-2024-6609 available for the nss version we have in Debian Bullseye = (nss 3.61).</div><div><br /></div><div>We have a note [0] that mentions thi= s:</div><div><br /></div><div>=3D=3D=3D 8< =3D=3D=3D<br /></div><div><sp= an><span>To address CVE in older versions of src:nss what is needed is to a= dd the error</span><br /><span>handling code (confirmed by upstream):</span= ><br /><a href=3D"https://searchfox.org/nss/rev/ba9330537e6e94971de8b9bc494= 60891b23afd4f/lib/freebl/ec.c#379-382">https://searchfox.org/nss/rev/ba9330= 537e6e94971de8b9bc49460891b23afd4f/lib/freebl/ec.c#379-382</a><br /><span>t= o the ec_NewKey function, in the cleanup section, after mp_clear and</span>= <br /><span>before `if (rv)`.</span></span></div><div>=3D=3D=3D 8< =3D= =3D=3D</div><div><br /></div><div>I was hoping that you could provide this = patch yourself, because I don't think just a copy/paste (like the note seem= s to suggest), would be enough.</div><div><br /></div><div>Please, let me k= now if you can help with this.</div><div><br /></div><div>thanks, regards.<= br /></div><div><br /></div><div>[0] https://security-tracker.debian.org/tr= acker/CVE-2024-6609</div><div><br /></div><div><br /></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;[email protected]" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">dev-tech= [email protected]</a>.<br /> To view this discussion on the web visit <a href=3D"https://groups.google.c= om/a/mozilla.org/d/msgid/dev-tech-crypto/66071e21-a687-49f2-a709-5244a06438= b6n%40mozilla.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.go= ogle.com/a/mozilla.org/d/msgid/dev-tech-crypto/66071e21-a687-49f2-a709-5244= a06438b6n%40mozilla.org</a>.<br /> ------=_Part_205739_1360410101.1727294571228-- ------=_Part_205738_190428022.1727294571228--