This bug was fixed in the package nss - 3.13.1.with.ckbi.1.88-1ubuntu1 --------------- nss (3.13.1.with.ckbi.1.88-1ubuntu1) precise; urgency=low
* Merge from Debian testing. Remaining changes: - Ship the main SO files in an unversioned binary, as we don't have versioned SO's in Ubuntu. Maintain a transitional versioned binary package containing the versioned symlinks, to maintain compatibility with Debian * update control, rules * mass rename libnss3-1d* => libnss3* - Fix postinst-must-call-ldconfig - dh_makeshlibs doesn't seem to add the maintainer script hooks with the unversioned SO files, so add them manually * add libnss3.postinst, libnss3.postrm - rules: Add support for mozilla-devscripts. - control: Change Vcs-* to XS-Debian-Vcs-*. * control: Fix typo (LP: #855424) * Bugs fixed by the merge: - Using dh now (LP: #613477) - Adds 85_security_load.patch (LP: #315096) nss (3.13.1.with.ckbi.1.88-1) unstable; urgency=low * New upstream release. - Distrusts malaysian Digicert Sdn. Bhd CA certificate. - Addresses CVE-2011-3640 (Untrusted search path vulnerability). Closes: #647614. * debian/patches/*: Refreshed patches. * debian/libnss3-1d.symbols: Add NSS 3.13 symbols. nss (3.12.11-3) unstable; urgency=high * mozilla/security/nss/lib/ckfw/builtins/certdata.*: Explicitely distrust various DigiNotar CAs: - DigiNotar Root CA - DigiNotar Services 1024 CA - DigiNotar Cyber CA - DigiNotar Cyber CA 2nd - DigiNotar PKIoverheid - DigiNotar PKIoverheid G2 nss (3.12.11-2) unstable; urgency=high * mozilla/security/nss/lib/ckfw/builtins/certdata.*: Remove DigiNotar Root CA. nss (3.12.11-1) unstable; urgency=low * New upstream release. * mozilla/security/nss/lib/ckfw/builtins/certdata.*, * mozilla/security/coreconf/{config,Linux}.mk: Refreshed. * debian/copyright: Update dbm license according to that in the source. Closes: #624310 nss (3.12.10-3) unstable; urgency=low * debian/nss-config.in, debian/nss.pc.in, debian/rules: Return the multiarch path in nss-config and nss.pc. nss (3.12.10-2) unstable; urgency=low * debian/control, debian/libnss3-1d.dirs, debian/libnss3-1d.lintian-overrides.in, debian/libnss3-dev.dirs, debian/libnss3-1d.links.in, debian/libnss3-dev.links.in, debian/rules: Switch to multi-arch while keeping backports easy. Closes: #497088. nss (3.12.10-1) unstable; urgency=low * New upstream release. * mozilla/security/nss/lib/ckfw/builtins/certdata.*: Refreshed. * debian/control: Build depend on libnspr4-dev >= 4.8.8. * debian/libnss3-1d.symbols: Add new symbol version. nss (3.12.9.with.ckbi.1.82-1) unstable; urgency=low * New upstream release. - Marks fraudulent Comodo certificates as untrusted. * mozilla/security/nss/lib/ckfw/builtins/certdata.*: Refreshed. -- Timo Aaltonen <tjaal...@ubuntu.com> Wed, 30 Nov 2011 11:16:39 +0200 ** Changed in: nss (Ubuntu) Status: In Progress => Fix Released ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2011-3640 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/315096 Title: signtool -L fails: "libsoftokn3.so: cannot open shared object file: No such file or directory" To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nss/+bug/315096/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs