opnsense / ports

OPNsense ports on top of FreeBSD
https://opnsense.org/
Other
157 stars 114 forks source link

CVE-2021-43527 NSS version that is vulnerable #137

Closed blubaustin closed 2 years ago

blubaustin commented 2 years ago

Important notices

Before you add a new report, we ask you kindly to acknowledge the following:

Is your feature request related to a problem? Please describe.

NSS is vunerable to memory corruption

Describe the solution you like Update the NSS version

"GOT REQUEST TO AUDIT SECURITY Currently running OPNsense 22.1.b_89 (amd64/OpenSSL) at Tue Dec 14 13:09:04 MST 2021 Fetching vuln.xml.bz2: .......... done nss-3.72 is vulnerable: NSS -- Memory corruption CVE: CVE-2021-43527 WWW: https://vuxml.FreeBSD.org/freebsd/47695a9c-5377-11ec-8be6-d4c9ef517024.html"

fichtner commented 2 years ago

Will be in 21.7.7.