about CVE-2024-7531 for nss 3.61 in Debian Bullseye

Arturo Borrero Gonzalez <[email protected]> Wed, 23 Oct 2024 04:01:25 -0700 (PDT)
Newsgroups gmane.comp.mozilla.crypto
Message-ID <[email protected]>
------=_Part_61676_417119510.1729681285935
Content-Type: multipart/alternative; 
	boundary="----=_Part_61677_1032891488.1729681285935"

------=_Part_61677_1032891488.1729681285935
Content-Type: text/plain; charset="UTF-8"

Hi there,

I'm interesting in having a patch for CVE-2024-7531 available for the nss 
version we have in Debian Bullseye (nss 3.61).

We have some information [0] about the code that introduced the 
vulnerability [1] and the patch that fixes it [2], but the patch does not 
apply cleanly to the code in 3.61, and I would kindly ask if you can double 
check it, and provide a patch that applies directly to that branch.

Please, let me know if you can help with this.

thanks, regards.

[0] https://deb.freexian.com/extended-lts/tracker/CVE-2024-7531
[1] 
https://hg.mozilla.org/projects/nss/rev/d5deac55f54350d60fd6ae69899ac399fdfcfc72
[2] 
https://hg.mozilla.org/projects/nss/rev/525c5044cc9e53f5015c697b04b1405df91003ac

-- 
You received this message because you are subscribed to the Google Groups "[email protected]" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion on the web visit https://groups.google.com/a/mozilla.org/d/msgid/dev-tech-crypto/10f28996-666b-4b16-bae0-1acf2daa4c15n%40mozilla.org.

------=_Part_61677_1032891488.1729681285935
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div>Hi there,</div><div><br /></div><div>I'm interesting in having a patch=
 for CVE-2024-7531 available for the nss version we have in Debian Bullseye=
 (nss 3.61).</div><div><br /></div><div>We have some information [0] about =
the code that introduced the vulnerability [1] and the patch that fixes it =
[2], but the patch does not apply cleanly to the code in 3.61, and I would =
kindly ask if you can double check it, and provide a patch that applies dir=
ectly to that branch.</div><div><br /></div><div>Please, let me know if you=
 can help with this.</div><div><br /></div><div>thanks, regards.<br /></div=
><div><br /></div><div>[0] https://deb.freexian.com/extended-lts/tracker/CV=
E-2024-7531</div><div>[1] https://hg.mozilla.org/projects/nss/rev/d5deac55f=
54350d60fd6ae69899ac399fdfcfc72</div><div>[2] https://hg.mozilla.org/projec=
ts/nss/rev/525c5044cc9e53f5015c697b04b1405df91003ac</div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;[email protected]&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">dev-tech=
[email protected]</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/mozilla.org/d/msgid/dev-tech-crypto/10f28996-666b-4b16-bae0-1acf2daa4c=
15n%40mozilla.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.go=
ogle.com/a/mozilla.org/d/msgid/dev-tech-crypto/10f28996-666b-4b16-bae0-1acf=
2daa4c15n%40mozilla.org</a>.<br />

------=_Part_61677_1032891488.1729681285935--

------=_Part_61676_417119510.1729681285935--