Gnoppix Security Issues Emergency Fix for NSS Memory Safety Flaw
GSA-6403-1 patches multiple memory safety bugs in the Network Security Services (NSS) library, posing immediate risk of data corruption or crashes.
Critical Flaw in Cryptographic Library
NSS, the core Mozilla cryptographic library, contained memory safety errors. These bugs could let attackers corrupt memory or crash applications using NSS for encryption or certificate handling.
Gnoppix Versions Affected
- Gnoppix 23/25 (old stable) and Gnoppix 25 (stable) both require urgent updates.
Immediate Action Required
Update the
nsspackage to version 2:3.110-1~deb12u1 (for Gnoppix 23/25) or 2:3.110-1 (for Gnoppix 25).
Background
Memory safety vulnerabilities in C-based libraries can lead to exploitable conditions. The fix addresses multiple issues discovered during upstream testing. - Please update your systems.