The updated packages fix a security vulnerability: The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octets must be applied. Therefore this bug allows an attacker to provide a truncated Authentication Tag and to modify the JWE . MGASA-2023-0350 - Updated cjose packages fix a security vulnerability Publication date: 18 Dec 2023 URL: https://advisories.mageia.org/MGASA-2023-0350.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-37464 The updated packages fix a security vulnerability: The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octets must be applied. Therefore this bug allows an attacker to provide a truncated Authentication Tag and to modify the JWE accordingly. (CVE-2023-37464) References: - https://bugs.mageia.org/show_bug.cgi?id=32274 - https://lists.fedoraproject.org/archives/list/
It was discovered that an incorrect implementation of AES GCM decryption in cjose, a C library implementing the JOSE standard may allow an attacker to provide a truncated Authentication Tag and modify the JWE object. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5472-1
Get the latest Linux and open source security news straight to your inbox.