Debian Security Advisory

DSA-2820-1 nspr -- integer overflow

Date Reported:
17 Dec 2013
Affected Packages:
nspr
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2013-5607.
More information:

It was discovered that NSPR, Netscape Portable Runtime library, could crash an application using the library when parsing a certificate that causes an integer overflow. This flaw only affects 64-bit systems.

For the oldstable distribution (squeeze), this problem has been fixed in version 4.8.6-1+squeeze1.

For the stable distribution (wheezy), this problem has been fixed in version 2:4.9.2-1+deb7u1.

For the testing distribution (jessie), and the unstable distribution (sid), this problem has been fixed in version 2:4.10.2-1.

We recommend that you upgrade your nspr packages.