The NSS Development Team announces multiple patch releases: * NSS 3.36.8 for NSS 3.36 * NSS 3.44.1 for NSS 3.44
No new functionality is introduced in these releases. The following fixes are included. Users are encouraged to upgrade. 3.36.8: * 1554336 - Optimize away unneeded loop in mpi.c * 1515342 - More thorough input checking * 1540541 - Don't unnecessarily strip leading 0's from key material during PKCS11 import 3.44.1: * 1554336 - Optimize away unneeded loop in mpi.c * 1515342 - More thorough input checking * 1540541 - Don't unnecessarily strip leading 0's from key material during PKCS11 import * 1515236 - Add a SSLKEYLOGFILE enable/disable flag at build.sh * 1546229 - Add IPSEC IKE support to softoken * 1473806 - Fix SECKEY_ConvertToPublicKey handling of non-RSA keys * 1546477 - Updates to testing for FIPS validation * 1552208 - Prohibit use of RSASSA-PKCS1-v1_5 algorithms in TLS 1.3 * 1551041 - Unbreak build on GCC < 4.3 big-endian NSS source distributions are available on ftp.mozilla.org for secure HTTPS download. NSS 3.36.8 requires NSPR 4.19 or newer. The HG tag is NSS_3_36_8_RTM. The full release notes are available at https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.8_release_notes Download: https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_36_8_RTM/src/ NSS 3.44.1 requires NSPR 4.21 or newer. The HG tag is NSS_3_44_1_RTM. The full release notes are available at https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.44.1_release_notes Download: https://ftp.mozilla.org/pub/security/nss/releases/NSS_3_44_1_RTM/src/ -- dev-tech-crypto mailing list dev-tech-crypto@lists.mozilla.org https://lists.mozilla.org/listinfo/dev-tech-crypto