about CVE-2024-7531 for nss 3.61 in Debian Bullseye
Arturo Borrero Gonzalez <[email protected]> Wed, 23 Oct 2024 04:01:25 -0700 (PDT)
| Newsgroups | gmane.comp.mozilla.crypto |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_61676_417119510.1729681285935 Content-Type: multipart/alternative; boundary="----=_Part_61677_1032891488.1729681285935" ------=_Part_61677_1032891488.1729681285935 Content-Type: text/plain; charset="UTF-8" Hi there, I'm interesting in having a patch for CVE-2024-7531 available for the nss version we have in Debian Bullseye (nss 3.61). We have some information [0] about the code that introduced the vulnerability [1] and the patch that fixes it [2], but the patch does not apply cleanly to the code in 3.61, and I would kindly ask if you can double check it, and provide a patch that applies directly to that branch. Please, let me know if you can help with this. thanks, regards. [0] https://deb.freexian.com/extended-lts/tracker/CVE-2024-7531 [1] https://hg.mozilla.org/projects/nss/rev/d5deac55f54350d60fd6ae69899ac399fdfcfc72 [2] https://hg.mozilla.org/projects/nss/rev/525c5044cc9e53f5015c697b04b1405df91003ac -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/10f28996-666b-4b16-bae0-1acf2daa4c15n%40mozilla.org. ------=_Part_61677_1032891488.1729681285935 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div>Hi there,</div><div><br /></div><div>I'm interesting in having a patch= for CVE-2024-7531 available for the nss version we have in Debian Bullseye= (nss 3.61).</div><div><br /></div><div>We have some information [0] about = the code that introduced the vulnerability [1] and the patch that fixes it = [2], but the patch does not apply cleanly to the code in 3.61, and I would = kindly ask if you can double check it, and provide a patch that applies dir= ectly to that branch.</div><div><br /></div><div>Please, let me know if you= can help with this.</div><div><br /></div><div>thanks, regards.<br /></div= ><div><br /></div><div>[0] https://deb.freexian.com/extended-lts/tracker/CV= E-2024-7531</div><div>[1] https://hg.mozilla.org/projects/nss/rev/d5deac55f= 54350d60fd6ae69899ac399fdfcfc72</div><div>[2] https://hg.mozilla.org/projec= ts/nss/rev/525c5044cc9e53f5015c697b04b1405df91003ac</div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;[email protected]" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">dev-tech= [email protected]</a>.<br /> To view this discussion on the web visit <a href=3D"https://groups.google.c= om/a/mozilla.org/d/msgid/dev-tech-crypto/10f28996-666b-4b16-bae0-1acf2daa4c= 15n%40mozilla.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.go= ogle.com/a/mozilla.org/d/msgid/dev-tech-crypto/10f28996-666b-4b16-bae0-1acf= 2daa4c15n%40mozilla.org</a>.<br /> ------=_Part_61677_1032891488.1729681285935-- ------=_Part_61676_417119510.1729681285935--