Alerts This Week
Warning Icon 1 469
Alerts This Week
Warning Icon 1 469

Ubuntu 22.04 LTS USN-6595-2 critical: pycryptodome information leak

Ubuntu Large Esm H500
PyCryptodome could be made to expose sensitive information.
==========================================================================
Ubuntu Security Notice USN-6595-1
January 23, 2024

pycryptodome vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS

Summary:

PyCryptodome could be made to expose sensitive information.

Software Description:
- pycryptodome: Cryptographic Python library

Details:

It was discovered that PyCryptodome had a timing side-channel when
performing OAEP decryption. A remote attacker could possibly use this issue
to recover sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
   python3-pycryptodome            3.11.0+dfsg1-3ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
   https://ubuntu.com/security/notices/USN-6595-1
   CVE-2023-52323

Package Information:
   https://launchpad.net/ubuntu/+source/pycryptodome/3.11.0+dfsg1-3ubuntu0.1

Ubuntu 22.04 LTS USN-6595-2 critical: pycryptodome information leak

ubuntu
Calendar Grey January 23, 2024
Dist Ubuntu Esm H88
Enhance your Ubuntu 22.04 LTS to rectify the PyCryptodome security flaw that threatens to reveal confidential information.
PyCryptodome could be made to expose sensitive information.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: PyCryptodome could be made to expose sensitive information. Software Description: - pycryptodome: Cryptographic Python library Details: It was discovered that PyCryptodome had a timing side-channel when performing OAEP decryption. A remote attacker could possibly use this issue to recover sensitive information.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: python3-pycryptodome 3.11.0+dfsg1-3ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6595-1

CVE-2023-52323

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6595-1

Package Information

https://launchpad.net/ubuntu/+source/pycryptodome/3.11.0+dfsg1-3ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here