Contains a fix for (CVE-2013-1740): When false start is enabled, libssl will sometimes return unencrypted, unauthenticated data from PR_Recv (https://bugzilla.mozilla.org/show_bug.cgi?id=919877) See https://developer.mozilla.org/en-US/docs/NSS/NSS_3.15.4_release_notes