Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security vulnerabilities have been discovered in golang-go.crypto, the supplementary Go cryptography libraries. CVE-2019-11840 . -------------------------------------------------------------------------Debian LTS Advisory DLA-3455-1
Moderate: openssl security and bug fix update. {"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2022:6224","synopsis":"Moderate: openssl security and bug fix update","severity":"SEVERITY_MODERATE","topic":"An update for openssl is now available for Rocky Linux 9.\nRocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.","description":"OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[{"ticket":"2080323","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2080323","description":"openssl occasionally sends internal error to gnutls when using FFDHE [rhel-9.0.0.z]"},{"ticket":"2081494","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2081494","description":"CVE-2022-1292 openssl: c_rehash script allows command injection"},{"ticket":"2082584","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2082584","description":"OpenSSL FIPS module should not build in non-approved algorithms [rhel-9.0.0.z]"},{"ticket":"2082585","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2082585","description":"Change FIPS module version to include hash of specfile, patches and sources [rhel-9.0.0.z]"},{"ticket":"2085499","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2085499","description":"openssl req defaults to 3DES[rhel-9.0.0.z]"},{"ticket":"2085500","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2085500","description":"Specifying the openssl config file explicitly causes provider initialisation to fail in FIPS mode [rhel-9.0.0.z]"},{"ticket":"2085521","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2085521","description":"OpenSSL mustn't work with ECDSA with explicit curve parameters in FIPS mode [rhel-9.0.0.z]"},{"ticket":"2086554","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2086554","description":"openssl s_server -groups secp256k1 in FIPS fails because X25519\/X448 [rhel-9.0.0.z]"},{"ticket":"2086866","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2086866","description":"Converting FIPS power-on self test to KAT [rhel-9.0.0.z]"},{"ticket":"2087234","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2087234","description":"openssl in FIPS mode verifies SHA-1 signatures, but should not [rhel-9.0.0.z]"},{"ticket":"2087911","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2087911","description":"CVE-2022-1343 openssl: Signer certificate verification returns inaccurate response when using OCSP_NOCHECKS"},{"ticket":"2087913","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2087913","description":"CVE-2022-1473 openssl: OPENSSL_LH_flush() breaks reuse of memory"},{"ticket":"2091938","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2091938","description":"Small RSA keys work for some operations in FIPS mode [rhel-9.0.0.z]"},{"ticket":"2091977","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2091977","description":"FIPS provider doesn't block RSA encryption for key transport [rhel-9.0.0.z]"},{"ticket":"2091994","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2091994","description":"Incompletefiltering of ciphersuites in FIPS mode [rhel-9.0.0.z]"},{"ticket":"2095696","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2095696","description":"OpenSSL testsuite certificates expired [rhel-9.0.0.z]"},{"ticket":"2097310","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2097310","description":"CVE-2022-2068 openssl: the c_rehash script allows command injection"},{"ticket":"2101346","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2101346","description":"PPC 64 Montgomery mult is buggy [rhel-9.0.0.z]"},{"ticket":"2104905","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2104905","description":"CVE-2022-2097 openssl: AES OCB fails to encrypt some bytes"},{"ticket":"2107530","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2107530","description":"sscg FTBFS in rhel-9.1 [rhel-9.0.0.z]"},{"ticket":"2112978","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2112978","description":"[FIPS lab review] self-test [rhel-9.0.0.z]"},{"ticket":"2115856","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2115856","description":"[FIPS lab review] DH tuning [rhel-9.0.0.z]"},{"ticket":"2115857","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2115857","description":"[FIPS lab review] EC tuning [rhel-9.0.0.z]"},{"ticket":"2115858","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2115858","description":"[FIPS lab review] RSA tuning [rhel-9.0.0.z]"},{"ticket":"2115859","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2115859","description":"[FIPS lab review] RAND tuning [rhel-9.0.0.z]"},{"ticket":"2115861","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2115861","description":"[FIPS lab review] zeroization [rhel-9.0.0.z]"},{"ticket":"2118388","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2118388","description":"[FIPS lab review] HKDF limitations [rhel-9.0.0.z]"}],"cves":[{"name":"CVE-2022-2068","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-2068.json","cvss3ScoringVector":"CVSS:3.1\/AV:L\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","cvss3BaseScore":"6.7","cwe":"CWE-77"}],"references":[],"publishedAt":"2023-01-25T21:21:29.199409Z","rpms":{},"rebootSuggested":false,"buildReferences":[]}. The latest OpenSSL update for Rocky Linux 9 tackles some moderate security threats. Ensure your systems remain protected by applying the newest patches.. Openssl Update, Rocky Linux Advisory, Security Alert, Bug Fix Alert. . LinuxSecurity.com Team
Several vulnerabilities were discovered in mbed TLS, a lightweight crypto and SSL/TLS library, which could result in denial of service, information disclosure or side-channel attacks. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2826-1
Security fix for CVE-2021-33560 (#1970098). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-31fdc84207 2021-07-01 01:12:48.702442 --------------------------------------------------------------------------------Name : libgcrypt Product : Fedora 34 Version : 1.9.3 Release : 3.fc34 URL : https://www.gnupg.org/ Summary : A general-purpose cryptography library Description : Libgcrypt is a general purpose crypto library based on the code used in GNU Privacy Guard. This is a development version. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-33560 (#1970098) --------------------------------------------------------------------------------ChangeLog: * Tue Jun 15 2021 Jakub Jelen - 1.9.3-3 - Fix for CVE-2021-33560 (#1970098) --------------------------------------------------------------------------------References: [ 1 ] Bug #1970096 - CVE-2021-33560 libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm https://bugzilla.redhat.com/show_bug.cgi?id=1970096 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-31fdc84207' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Minor bug and security fix release 1.8.5.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-6c96156c32 2019-09-18 00:01:15.681852 --------------------------------------------------------------------------------Name : libgcrypt Product : Fedora 31 Version : 1.8.5 Release : 1.fc31 URL : http://www.gnupg.org/ Summary : A general-purpose cryptography library Description : Libgcrypt is a general purpose crypto library based on the code used in GNU Privacy Guard. This is a development version. --------------------------------------------------------------------------------Update Information: Minor bug and security fix release 1.8.5. --------------------------------------------------------------------------------References: [ 1 ] Bug #1747116 - libgcrypt-1.8.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1747116 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-6c96156c32' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Two vulnerabilities were discovered in mbedtls, a lightweight crypto and SSL/TLS library which could result in plain text recovery via side-channel attacks. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4296-1
Minor security update release 1.7.9.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-bcdeca9d41 2017-11-07 21:00:14.744151 --------------------------------------------------------------------------------Name : libgcrypt Product : Fedora 26 Version : 1.7.9 Release : 1.fc26 URL : http://www.gnupg.org/ Summary : A general-purpose cryptography library Description : Libgcrypt is a general purpose crypto library based on the code used in GNU Privacy Guard. This is a development version. --------------------------------------------------------------------------------Update Information: Minor security update release 1.7.9. --------------------------------------------------------------------------------References: [ 1 ] Bug #1485921 - CVE-2017-0379 libgcrypt: Missing input validation for X25519 curve https://bugzilla.redhat.com/show_bug.cgi?id=1485921 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libgcrypt' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Aleksandar Nikolic discovered that an error in the x509 parser of the Botan crypto library could result in an out-of-bounds memory read, resulting in denial of service or an information leak if processing a malformed certificate. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3939-1
Get the latest Linux and open source security news straight to your inbox.