Rocky Linux: RLSA-2023:1067 pesign security update | LinuxSecurity...
{"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2023:1067","synopsis":"Important: pesign security update","severity":"SEVERITY_IMPORTANT","topic":"An update is available for pesign.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools.\n\nSecurity Fix(es):\n\n* pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[{"ticket":"2135420","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2135420","description":""}],"cves":[{"name":"CVE-2022-3560","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-3560","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"}],"references":[],"publishedAt":"2023-03-08T16:38:25.971989Z","rpms":{"Rocky Linux 9":{"nvras":["pesign-0:115-6.el9_1.rocky.2.aarch64.rpm","pesign-0:115-6.el9_1.rocky.2.src.rpm","pesign-0:115-6.el9_1.rocky.2.x86_64.rpm","pesign-debuginfo-0:115-6.el9_1.rocky.2.aarch64.rpm","pesign-debuginfo-0:115-6.el9_1.rocky.2.x86_64.rpm","pesign-debugsource-0:115-6.el9_1.rocky.2.aarch64.rpm","pesign-debugsource-0:115-6.el9_1.rocky.2.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}

Rocky Linux: RLSA-2023:1067 pesign security update

March 8, 2023
An update is available for pesign. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list

Summary

An update is available for pesign. This update affects Rocky Linux 9. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list


The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools. Security Fix(es): * pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

RPMs

pesign-0:115-6.el9_1.rocky.2.aarch64.rpm

pesign-0:115-6.el9_1.rocky.2.src.rpm

pesign-0:115-6.el9_1.rocky.2.x86_64.rpm

pesign-debuginfo-0:115-6.el9_1.rocky.2.aarch64.rpm

pesign-debuginfo-0:115-6.el9_1.rocky.2.x86_64.rpm

pesign-debugsource-0:115-6.el9_1.rocky.2.aarch64.rpm

pesign-debugsource-0:115-6.el9_1.rocky.2.x86_64.rpm

References

No References

CVEs

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3560

Severity
Name: RLSA-2023:1067
Affected Products: Rocky Linux 9

Fixes

https://bugzilla.redhat.com/show_bug.cgi?id=2135420


We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.