- ------------------------------------------------------------------------- Debian LTS Advisory DLA-3648-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb November 07, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : tang Version : 7-1+deb10u2 CVE ID : CVE-2023-1672 Debian Bug : 1038119 It was discovered that there was a race condition in Tang, a network-based cryptographic binding server. This flaw resulted in a small time window whereby newly-generated private keys were readable by other processes on the same machine. For Debian 10 buster, this problem has been fixed in version 7-1+deb10u2. We recommend that you upgrade your tang packages. For the detailed security status of tang please refer to its security tracker page at: https://security-tracker.debian.org/tracker/tang Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS