Mozilla Network Security Service (NSS): Multiple vulnerabilities NSS has multiple information disclosure vulnerabilities when handling secret key material. nss 2020-08-19 2020-08-19 734986 local, remote 3.55 3.55

The Mozilla Network Security Service (NSS) is a library implementing security features like SSL v.2/v.3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME and X.509 certificates.

Multiple vulnerabilities have been discovered in NSS. Please review the CVE identifiers referenced below for details.

An attacker may be able to obtain information about secret key material.

There is no known workaround at this time.

All NSS users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/nss-3.55"
CVE-2020-12400 CVE-2020-12401 CVE-2020-12403 sam_c sam_c