Debian Security Advisory DSA 2490-1 (nss)

Summary
The remote host is missing an update to nss announced via advisory DSA 2490-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%202490-1
Insight
Kaspar Brand discovered that Mozilla's Network Security Services (NSS) library did insufficient length checking in the QuickDER decoder, allowing to crash a program using the library. For the stable distribution (squeeze), this problem has been fixed in version 3.12.8-1+squeeze5. For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 2:3.13.4-3. We recommend that you upgrade your nss packages.