Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
217

Oracle Linux 9 ELSA-2023-4411 Important: CJose AES Decryption Fix

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4411 https://linux.oracle.com/errata/ELSA-2023-4411.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: cjose-0.6.1-13.el9_2.i686.rpm cjose-0.6.1-13.el9_2.x86_64.rpm aarch64: cjose-0.6.1-13.el9_2.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//cjose-0.6.1-13.el9_2.src.rpm Related CVEs: CVE-2023-37464 Description of changes: [0.6.1-13] - CVE-2023-37464 cjose: AES GCM decryption uses the Tag length from the actual Authentication Tag provided in the JWE Resolves: rhbz#2223308 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2023-4422 addresses a critical issue in CJose, fixing vulnerabilities related to AES GCM encryption flaws.. Oracle Linux Update,Linux Security Advisory,CJose Fix,AES Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 10, 2023 Important Oracle
98

Red Hat Enterprise Linux 9.0: Important Security Issue RHSA-2023:4417-01

An update for cjose is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: cjose security update Advisory ID: RHSA-2023:4417-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4417 Issue date: 2023-08-01 CVE Names: CVE-2023-37464 ===================================================================== 1. Summary: An update for cjose is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 3. Description: CJose is C library implementing the Javascript Object Signing and Encryption (JOSE). Security Fix(es): * cjose: AES GCM decryption uses the Tag length from the actual Authentication Tag provided in the JWE (CVE-2023-37464) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2223295 - CVE-2023-37464 cjose: AES GCM decryption uses the Tag length from the actual Authentication Tag provided in the JWE 6. Package List: Red HatEnterprise Linux AppStream EUS (v.9.0): Source: cjose-0.6.1-13.el9_0.src.rpm aarch64: cjose-0.6.1-13.el9_0.aarch64.rpm cjose-debuginfo-0.6.1-13.el9_0.aarch64.rpm cjose-debugsource-0.6.1-13.el9_0.aarch64.rpm ppc64le: cjose-0.6.1-13.el9_0.ppc64le.rpm cjose-debuginfo-0.6.1-13.el9_0.ppc64le.rpm cjose-debugsource-0.6.1-13.el9_0.ppc64le.rpm s390x: cjose-0.6.1-13.el9_0.s390x.rpm cjose-debuginfo-0.6.1-13.el9_0.s390x.rpm cjose-debugsource-0.6.1-13.el9_0.s390x.rpm x86_64: cjose-0.6.1-13.el9_0.i686.rpm cjose-0.6.1-13.el9_0.x86_64.rpm cjose-debuginfo-0.6.1-13.el9_0.i686.rpm cjose-debuginfo-0.6.1-13.el9_0.x86_64.rpm cjose-debugsource-0.6.1-13.el9_0.i686.rpm cjose-debugsource-0.6.1-13.el9_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-37464 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkyWl9AAoJENzjgjWX9erEqvcP/R5BKB67az6ZMnARR/AVk0BW 4OOVs1g1JPCsaqu8oVolYl2cobJt7XzqrxuXLoGwA5rxcJU/kaK3kLXE3Eq05hXW kO6C+qL8dHwm266VaRSWZCVoriYQF1kH7P6mJUU99Z0x15Oh0UNG8hTyQh16JAtv Rdgpe7DDpy44VwnGD8rtjTsHybYC9YuRJ7qyTpIHp30QoIYNrXVQwkCMeDvOPwD+ FooRZcv9ItfBJSXJlGiB4MJ872uWGjqCP/SX/uAE88KBYk++SFxg91MDm0mlEMFf +52AtQE09f+Hq5Iu3cDGj6IsHrTxzyawGjIaJZGhISk6268u9zUq55kGsYdOIPB0 0puaDwWIu58Gwyy4YrOhcr+TGv4ShmNufotGgpV2dV8USsz6nrGd9WWZrapwq38J IHuCRS5H4edrv/HkyzXytDUQhFTjJGKEf9L0yTK8D99wpFT+voIfFo6yT8pYEw76 bnkfypUsdLkyLnMiuLCsv6CY9INydP+wmiRoWrKotJ0d/i1HDH8MFZ3il1MGazXF sxtszOQwwRKMy+uZxBV5S+dVo2GYhorpq946Nd1gyvG2xhjOQAhrrUUr9++2dOfX AJ5fz9wylbQ0E8Wn5u383TtIny+vszCHjPtkd8jyKyAt8HcPdbd7Eik/eOf/f3Tw PYoTlkixsRgXhamJTYvG =Yz/C -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. .Crucial notification for cjose in Red Hat 9.0 EUS classified as a significant security issue. Implement the most recent protective protocols immediately.. Red Hat Update,CJose Security,Important Advisory,AES Decryption,Enterprise Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 01, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here