Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Upstream details at : https://access.redhat.com/errata/RHSA-2023:0530. CentOS Errata and Security Advisory 2023:0530 Important Upstream details at : https://access.redhat.com/errata/RHSA-2023:0530 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 09f2614aeded0a8d1f7454f0270fe81a129ba048470ed9851001049d758c2a0f libksba-1.3.0-7.el7_9.i686.rpm b93825bf103f570b5e1032748e404b0d685f2025279cdfd1efbd0506671dd269 libksba-1.3.0-7.el7_9.x86_64.rpm d66f8f50f89a80ba6132ad39773812f3a9b5d598db35a63de6e8465c3c7137d8 libksba-devel-1.3.0-7.el7_9.i686.rpm 082abb4e91620918c0d5d1da8dfb191f950c793d112a4ac3ec4f2055ca594c68 libksba-devel-1.3.0-7.el7_9.x86_64.rpm Source: 3e26e87673f1bf593161fedcff13c52a5f4cd7708824d3d04c4a43b955749c98 libksba-1.3.0-7.el7_9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0625 https://linux.oracle.com/errata/ELSA-2023-0625.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libksba-1.3.5-9.el8_7.i686.rpm libksba-1.3.5-9.el8_7.x86_64.rpm libksba-devel-1.3.5-9.el8_7.i686.rpm libksba-devel-1.3.5-9.el8_7.x86_64.rpm aarch64: libksba-1.3.5-9.el8_7.aarch64.rpm libksba-devel-1.3.5-9.el8_7.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//libksba-1.3.5-9.el8_7.src.rpm Related CVEs: CVE-2022-47629 Description of changes: [1.3.5-9] - Fix for CVE-2022-47629 (#2161571) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0626 https://linux.oracle.com/errata/ELSA-2023-0626.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: libksba-1.5.1-6.el9_1.i686.rpm libksba-1.5.1-6.el9_1.x86_64.rpm libksba-devel-1.5.1-6.el9_1.i686.rpm libksba-devel-1.5.1-6.el9_1.x86_64.rpm aarch64: libksba-1.5.1-6.el9_1.aarch64.rpm libksba-devel-1.5.1-6.el9_1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//libksba-1.5.1-6.el9_1.src.rpm Related CVEs: CVE-2022-47629 Description of changes: [1.5.1-6] - Fix for CVE-2022-47629 (#2161571) _______________________________________________ El-errata mailing list
An update for libksba is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libksba security update Advisory ID: RHSA-2023:0625-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0625 Issue date: 2023-02-07 CVE Names: CVE-2022-47629 ==================================================================== 1. Summary: An update for libksba is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building blocks of S/MIME and TLS. Security Fix(es): * libksba: integer overflow to code executiona (CVE-2022-47629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161571 - CVE-2022-47629libksba: integer overflow to code execution 6. Package List: Red Hat Enterprise Linux BaseOS (v. 8): Source: libksba-1.3.5-9.el8_7.src.rpm aarch64: libksba-1.3.5-9.el8_7.aarch64.rpm libksba-debuginfo-1.3.5-9.el8_7.aarch64.rpm libksba-debugsource-1.3.5-9.el8_7.aarch64.rpm ppc64le: libksba-1.3.5-9.el8_7.ppc64le.rpm libksba-debuginfo-1.3.5-9.el8_7.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_7.ppc64le.rpm s390x: libksba-1.3.5-9.el8_7.s390x.rpm libksba-debuginfo-1.3.5-9.el8_7.s390x.rpm libksba-debugsource-1.3.5-9.el8_7.s390x.rpm x86_64: libksba-1.3.5-9.el8_7.i686.rpm libksba-1.3.5-9.el8_7.x86_64.rpm libksba-debuginfo-1.3.5-9.el8_7.i686.rpm libksba-debuginfo-1.3.5-9.el8_7.x86_64.rpm libksba-debugsource-1.3.5-9.el8_7.i686.rpm libksba-debugsource-1.3.5-9.el8_7.x86_64.rpm Red Hat CodeReady Linux Builder (v. 8): aarch64: libksba-debuginfo-1.3.5-9.el8_7.aarch64.rpm libksba-debugsource-1.3.5-9.el8_7.aarch64.rpm libksba-devel-1.3.5-9.el8_7.aarch64.rpm ppc64le: libksba-debuginfo-1.3.5-9.el8_7.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_7.ppc64le.rpm libksba-devel-1.3.5-9.el8_7.ppc64le.rpm s390x: libksba-debuginfo-1.3.5-9.el8_7.s390x.rpm libksba-debugsource-1.3.5-9.el8_7.s390x.rpm libksba-devel-1.3.5-9.el8_7.s390x.rpm x86_64: libksba-debuginfo-1.3.5-9.el8_7.i686.rpm libksba-debuginfo-1.3.5-9.el8_7.x86_64.rpm libksba-debugsource-1.3.5-9.el8_7.i686.rpm libksba-debugsource-1.3.5-9.el8_7.x86_64.rpm libksba-devel-1.3.5-9.el8_7.i686.rpm libksba-devel-1.3.5-9.el8_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY+LB69zjgjWX9erEAQgwgQ//TOfGLw9P8i1SiIsgoMSWA8y/mSHECodZ W9SJ3GJEweov9Lw4m5Fwqq7G51OPFp6C9dRs9VzFc2BwTHOXiTNJCrjHtWSeDRZu TKrEvMinupIRWtEQ8tPjUFjnbhzNI7IekTNOjvGNomNmuyE0rafz5eBrcH5b952Y hFurWEv5e4wUFICg2J4fZNbeB1ncGLu5mjJP6bnuOoEeNX9hTr7CAWgIJJPRa4gC b1dk08bPcwJSWoRS+ug6w+traOl6JAoJEmlU6DKdinADqGxH8rHOHdduwwZFgrOo E2BrafpikwLEtNvKOPRDBisYr4ItG4NPFR49XEhJGHILfufNvMCNLeaFZFrryZBI ovSAg4qmmgr8qStK+1gREe1wVWyLMX4wTlUMEFwKQzq7gsSsDhgfWYDEUA0GpAB1 q0GZW+IHtCLN4IALbatCmE8D/NFSPpKF4jgLr0Dy7z+vuvzfrgSYcbzNpgqR4Sws 7Olq1/e0ap7Sdn8kopz/lsLs8Khw4AwJWvQvSkxKNa7L6scYDks2WzwcYzqZtmEm Spei9SfABBtZFZU9JDR4PDDQdq6KJauBnwoicwsnCS6s0a9MpOV1iekWnuZliFIf +qcuykbsZUejOJZ0te10KZbPT4OKysfg+9C8gAoRa1thM4T+AmRcyhOlrT9HZTlI gatPGulwdxg=XvOg -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for libksba is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libksba security update Advisory ID: RHSA-2023:0624-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0624 Issue date: 2023-02-07 CVE Names: CVE-2022-47629 ==================================================================== 1. Summary: An update for libksba is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v. 8.4) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.8.4) - aarch64, ppc64le, s390x, x86_64 3. Description: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building blocks of S/MIME and TLS. Security Fix(es): * libksba: integer overflow to code executiona (CVE-2022-47629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161571 - CVE-2022-47629 libksba:integer overflow to code execution 6. Package List: Red Hat Enterprise Linux BaseOS EUS (v.8.4): Source: libksba-1.3.5-9.el8_4.src.rpm aarch64: libksba-1.3.5-9.el8_4.aarch64.rpm libksba-debuginfo-1.3.5-9.el8_4.aarch64.rpm libksba-debugsource-1.3.5-9.el8_4.aarch64.rpm ppc64le: libksba-1.3.5-9.el8_4.ppc64le.rpm libksba-debuginfo-1.3.5-9.el8_4.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_4.ppc64le.rpm s390x: libksba-1.3.5-9.el8_4.s390x.rpm libksba-debuginfo-1.3.5-9.el8_4.s390x.rpm libksba-debugsource-1.3.5-9.el8_4.s390x.rpm x86_64: libksba-1.3.5-9.el8_4.i686.rpm libksba-1.3.5-9.el8_4.x86_64.rpm libksba-debuginfo-1.3.5-9.el8_4.i686.rpm libksba-debuginfo-1.3.5-9.el8_4.x86_64.rpm libksba-debugsource-1.3.5-9.el8_4.i686.rpm libksba-debugsource-1.3.5-9.el8_4.x86_64.rpm Red Hat CodeReady Linux Builder EUS (v. 8.4): aarch64: libksba-debuginfo-1.3.5-9.el8_4.aarch64.rpm libksba-debugsource-1.3.5-9.el8_4.aarch64.rpm libksba-devel-1.3.5-9.el8_4.aarch64.rpm ppc64le: libksba-debuginfo-1.3.5-9.el8_4.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_4.ppc64le.rpm libksba-devel-1.3.5-9.el8_4.ppc64le.rpm s390x: libksba-debuginfo-1.3.5-9.el8_4.s390x.rpm libksba-debugsource-1.3.5-9.el8_4.s390x.rpm libksba-devel-1.3.5-9.el8_4.s390x.rpm x86_64: libksba-debuginfo-1.3.5-9.el8_4.i686.rpm libksba-debuginfo-1.3.5-9.el8_4.x86_64.rpm libksba-debugsource-1.3.5-9.el8_4.i686.rpm libksba-debugsource-1.3.5-9.el8_4.x86_64.rpm libksba-devel-1.3.5-9.el8_4.i686.rpm libksba-devel-1.3.5-9.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY+LB5tzjgjWX9erEAQhz3Q/+IBDQSsEoC1UXF9BMRv/pT6gh62enh/PV 3zHSkgKJgzA+Pry7REsTXjim/8i6590eHLk2u07j/d8epaZnY4mbUQlWi7QTYtfE rzupHfnIAmxO5ASiBT+QzrpRZXJXO2hm9n/ze45mP5FtZ+a4pgEnBDywowBeQ9Oh HsvIUaWinOGqZWzPxRS5+ZlApbbLGSZ6H5BWRBOZSZao3d1fNrO1xryRtSK8uJd8 B8KFlYwzpE0IbM7TOTqs8OjPnzjmDJP6a6sArKbMIpKBBfHSNt/cy8pkzsal046w H68GmbshRn7EqFTh5WNm1jVZX3dOChYfpstNIyaYWhDDt2A0SBmmp43jUHwnL62G wS2kwcXTALy6Y5YWuXtPuvITWjC1ZVUYjBm3z4VXQ/tv5uaoRL/fiJi+RjoCZ402 HaFW++cH3Ue2Eh4YiulxYku3Efdm+yUVMQVj7vhO4k3Euf1ecyrKBrEzxZwbWU0P oZs6fGtnXSv/zB5xq3C8jijvhJc4Nht/alawrMbILyGJM1ZodKTPeaaBG+4vsj6M iubnuCikJaPuSAOQPeophqL8U/k45+Yg/VJfvtUzAnBGRcdvzXKgd9aBJorSife/ 3655YKu9TU5UoCz4Sq3kkJ6iiknRDAFTTIxCgOgL3vBo5RemlltmKBSJ4QpNEqJF 53UTfg3c74c=yv2v -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for libksba is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libksba security update Advisory ID: RHSA-2023:0626-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0626 Issue date: 2023-02-07 CVE Names: CVE-2022-47629 ==================================================================== 1. Summary: An update for libksba is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building blocks of S/MIME and TLS. Security Fix(es): * libksba: integer overflow to code executiona (CVE-2022-47629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161571 - CVE-2022-47629libksba: integer overflow to code execution 6. Package List: Red Hat Enterprise Linux BaseOS (v. 9): Source: libksba-1.5.1-6.el9_1.src.rpm aarch64: libksba-1.5.1-6.el9_1.aarch64.rpm libksba-debuginfo-1.5.1-6.el9_1.aarch64.rpm libksba-debugsource-1.5.1-6.el9_1.aarch64.rpm ppc64le: libksba-1.5.1-6.el9_1.ppc64le.rpm libksba-debuginfo-1.5.1-6.el9_1.ppc64le.rpm libksba-debugsource-1.5.1-6.el9_1.ppc64le.rpm s390x: libksba-1.5.1-6.el9_1.s390x.rpm libksba-debuginfo-1.5.1-6.el9_1.s390x.rpm libksba-debugsource-1.5.1-6.el9_1.s390x.rpm x86_64: libksba-1.5.1-6.el9_1.i686.rpm libksba-1.5.1-6.el9_1.x86_64.rpm libksba-debuginfo-1.5.1-6.el9_1.i686.rpm libksba-debuginfo-1.5.1-6.el9_1.x86_64.rpm libksba-debugsource-1.5.1-6.el9_1.i686.rpm libksba-debugsource-1.5.1-6.el9_1.x86_64.rpm Red Hat CodeReady Linux Builder (v. 9): aarch64: libksba-debuginfo-1.5.1-6.el9_1.aarch64.rpm libksba-debugsource-1.5.1-6.el9_1.aarch64.rpm libksba-devel-1.5.1-6.el9_1.aarch64.rpm ppc64le: libksba-debuginfo-1.5.1-6.el9_1.ppc64le.rpm libksba-debugsource-1.5.1-6.el9_1.ppc64le.rpm libksba-devel-1.5.1-6.el9_1.ppc64le.rpm s390x: libksba-debuginfo-1.5.1-6.el9_1.s390x.rpm libksba-debugsource-1.5.1-6.el9_1.s390x.rpm libksba-devel-1.5.1-6.el9_1.s390x.rpm x86_64: libksba-debuginfo-1.5.1-6.el9_1.i686.rpm libksba-debuginfo-1.5.1-6.el9_1.x86_64.rpm libksba-debugsource-1.5.1-6.el9_1.i686.rpm libksba-debugsource-1.5.1-6.el9_1.x86_64.rpm libksba-devel-1.5.1-6.el9_1.i686.rpm libksba-devel-1.5.1-6.el9_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY+LB49zjgjWX9erEAQh6hQ/9F68BdUcgnwMw3z4vucBNukU19mtYUw7t ZjIRUmx5WT9AolFwpkRYE/hIcceyITU5q1ctFsN5JPKguTX8Qgnxv02L0t4zmSno k1vIbRsO2JXLafIa0V4Dr2HWwp98B0730iQlss5n3KN5Htfb10oEsICXh+j33TCp n277oSzikWlVrMjS0hqQ9vgWmju5tTTtnGkfsRXVGPNzfcJr7a4RpHecaruNphwf B6D3XybEuSnpMa6EHfyBKQVqVfwh9MlhV/0NbEwGk/J7Aiy8jrbbyifRGawfICbA 1Tnu0KsBLfFpvQIibZeZEmZQvCq/ET/7pbknDJ6U0wiLGQyxExEN5zm5l3FdKgcU LgDGCq2aUMFNEEa3WBtcgtXU5+rEBUetMiviUvP44edwuQMv1NodpBLDcSOFI9wo kHJFrhlFmd5SBJg3YTr74vZHooylFyR2rHCcMbPgM9E0LgDc2Osi6BwaUy6nBDxJ Q1EJlxzlNKUqyWxoRz4NgPirk9DPGeT22Mkrd+dKcpivy2H0B7DGJ4atwkIfZHIQ 0EKtb2/v0spBNKLqYIDMB2YjUqd0PSLGjx6Z+QNRA/5aq9q0kzDbsNUnqpZkSjT3 xJEBrLzKlTnPagOEnAKU88Vkek7472cDvjx1UaarEZSL8kXoRn99RGUL7IvKcbKv q88rwrvMLSA=kZUq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for libksba is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libksba security update Advisory ID: RHSA-2023:0629-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0629 Issue date: 2023-02-07 CVE Names: CVE-2022-47629 ==================================================================== 1. Summary: An update for libksba is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 3. Description: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building blocks of S/MIME and TLS. Security Fix(es): * libksba: integer overflow to code executiona (CVE-2022-47629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161571 - CVE-2022-47629 libksba:integer overflow to code execution 6. Package List: Red Hat Enterprise Linux BaseOS EUS (v.9.0): Source: libksba-1.5.1-6.el9_0.src.rpm aarch64: libksba-1.5.1-6.el9_0.aarch64.rpm libksba-debuginfo-1.5.1-6.el9_0.aarch64.rpm libksba-debugsource-1.5.1-6.el9_0.aarch64.rpm ppc64le: libksba-1.5.1-6.el9_0.ppc64le.rpm libksba-debuginfo-1.5.1-6.el9_0.ppc64le.rpm libksba-debugsource-1.5.1-6.el9_0.ppc64le.rpm s390x: libksba-1.5.1-6.el9_0.s390x.rpm libksba-debuginfo-1.5.1-6.el9_0.s390x.rpm libksba-debugsource-1.5.1-6.el9_0.s390x.rpm x86_64: libksba-1.5.1-6.el9_0.i686.rpm libksba-1.5.1-6.el9_0.x86_64.rpm libksba-debuginfo-1.5.1-6.el9_0.i686.rpm libksba-debuginfo-1.5.1-6.el9_0.x86_64.rpm libksba-debugsource-1.5.1-6.el9_0.i686.rpm libksba-debugsource-1.5.1-6.el9_0.x86_64.rpm Red Hat CodeReady Linux Builder EUS (v.9.0): aarch64: libksba-debuginfo-1.5.1-6.el9_0.aarch64.rpm libksba-debugsource-1.5.1-6.el9_0.aarch64.rpm libksba-devel-1.5.1-6.el9_0.aarch64.rpm ppc64le: libksba-debuginfo-1.5.1-6.el9_0.ppc64le.rpm libksba-debugsource-1.5.1-6.el9_0.ppc64le.rpm libksba-devel-1.5.1-6.el9_0.ppc64le.rpm s390x: libksba-debuginfo-1.5.1-6.el9_0.s390x.rpm libksba-debugsource-1.5.1-6.el9_0.s390x.rpm libksba-devel-1.5.1-6.el9_0.s390x.rpm x86_64: libksba-debuginfo-1.5.1-6.el9_0.i686.rpm libksba-debuginfo-1.5.1-6.el9_0.x86_64.rpm libksba-debugsource-1.5.1-6.el9_0.i686.rpm libksba-debugsource-1.5.1-6.el9_0.x86_64.rpm libksba-devel-1.5.1-6.el9_0.i686.rpm libksba-devel-1.5.1-6.el9_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY+LB0dzjgjWX9erEAQiUPg//W1/3L0V9rymcdNRGNelht4gpOiiMw1lq f7S+2UXQaNBTgpnGBCGL9mF91+2IVhA4lyDi8WgmMdmMW2BcnnVXa80KMkRaVg3T iMDqitxSjk0Db2tU0LC1tuou1RJ2pUTOPKhi6bd22rRinHAfQgH+K+On9iUQCMWj KHngivW6CSM0ibq4ucyjKsPjyoRvNlSccWMB5Lmrf0SBqYGysPr4Bvg08aCyKvhR skFfGPolvPAeW5TbLsgis2drh/a5sErxTZP2rBxfWO5JXJZpeXFvFE2zcnSbARWX 3NtM5L+I6IT4fT3HSKm3tVF4Wi0RMRw940libTQqpmLfDaSahLJcm97KhasN4qm0 9SPd6mPntbBcfiSBU/ljkSOUJE+tEN3rNR3Vomnq587bmznMuvL9Og9P6L6LsxP5 K85M1KLaqEo6C3jw2Q/UOxO/ETQicHidAJ6Q2pGIt5n5DtGN8qmGXKS1yQsy6AvD 5hW42yVfKhHHqw2LYeWfs9S4jdru6CaIpV+6QK2PCYOp1G3wZL0GFH4nnsfIKUnQ ILxFhIiAO9/06SUD8x94w/FXI0fnzFFoIKvYJwMH2krwe9vMRWGrcu7s1HzmqlLJ PcMJqJjMdo+MDq2vZxtc4Mi6nTKmLiymXZh0pawe/0g1jSxqOjcsMg7EOWqyjhoN ac5VK3Ebnrk=ssrX -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for libksba is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libksba security update Advisory ID: RHSA-2023:0594-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0594 Issue date: 2023-02-06 CVE Names: CVE-2022-47629 ==================================================================== 1. Summary: An update for libksba is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 3. Description: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building blocks of S/MIME and TLS. Security Fix(es): * libksba: integer overflow to code executiona (CVE-2022-47629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161571 - CVE-2022-47629 libksba:integer overflow to code execution 6. Package List: Red Hat Enterprise Linux BaseOS EUS (v.8.6): Source: libksba-1.3.5-9.el8_6.src.rpm aarch64: libksba-1.3.5-9.el8_6.aarch64.rpm libksba-debuginfo-1.3.5-9.el8_6.aarch64.rpm libksba-debugsource-1.3.5-9.el8_6.aarch64.rpm ppc64le: libksba-1.3.5-9.el8_6.ppc64le.rpm libksba-debuginfo-1.3.5-9.el8_6.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_6.ppc64le.rpm s390x: libksba-1.3.5-9.el8_6.s390x.rpm libksba-debuginfo-1.3.5-9.el8_6.s390x.rpm libksba-debugsource-1.3.5-9.el8_6.s390x.rpm x86_64: libksba-1.3.5-9.el8_6.i686.rpm libksba-1.3.5-9.el8_6.x86_64.rpm libksba-debuginfo-1.3.5-9.el8_6.i686.rpm libksba-debuginfo-1.3.5-9.el8_6.x86_64.rpm libksba-debugsource-1.3.5-9.el8_6.i686.rpm libksba-debugsource-1.3.5-9.el8_6.x86_64.rpm Red Hat CodeReady Linux Builder EUS (v.8.6): aarch64: libksba-debuginfo-1.3.5-9.el8_6.aarch64.rpm libksba-debugsource-1.3.5-9.el8_6.aarch64.rpm libksba-devel-1.3.5-9.el8_6.aarch64.rpm ppc64le: libksba-debuginfo-1.3.5-9.el8_6.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_6.ppc64le.rpm libksba-devel-1.3.5-9.el8_6.ppc64le.rpm s390x: libksba-debuginfo-1.3.5-9.el8_6.s390x.rpm libksba-debugsource-1.3.5-9.el8_6.s390x.rpm libksba-devel-1.3.5-9.el8_6.s390x.rpm x86_64: libksba-debuginfo-1.3.5-9.el8_6.i686.rpm libksba-debuginfo-1.3.5-9.el8_6.x86_64.rpm libksba-debugsource-1.3.5-9.el8_6.i686.rpm libksba-debugsource-1.3.5-9.el8_6.x86_64.rpm libksba-devel-1.3.5-9.el8_6.i686.rpm libksba-devel-1.3.5-9.el8_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY+FwatzjgjWX9erEAQjkEQ/+MjgHxmWjyizq0RATTn3EmEFo4zRkuT7/ xMuwNFp0nM/oG0s+PSGHosHEb9qIHvEOVSABWIAV5YsrPDtulL5j2YpdsFcYq9Xf 19X5gY7TUt1yaIDykxxnyWs1fP/8551J8WtwSOPk5hGAcULBd9QmllCjIjernWnj PfKvqvPl3us4fBHwiwO2FFPT8/ddUcKuDXMyHMWwRVyolfLI71lScF/J4/bCNZOh gCE1ujmEnsCDenyWr2Zk6Q+rq+xMVIxlNGI4wXKqAi1izaA1rMjsCdaIBabcMhBL EQxJ04oFlGUvB4obCWPzTdnInBanH64WiNbZWzI8/zMCxRh83Qx2rmMV0+ie455q nTTu2HNFRRMto8MKZSInKkbA3EfBo1S0dNSNnCAtsYm+3pCQry9kzbLssdcbqdSq WRELA5Em8RQqwxg+6+HRvk4D6jKl8rAd37qcDBSbL1XKvhIKk3O3/bgLzgKdopTB L0rFPLv8VAELGyRbnZ9nTZHjHZYOmk07ula+sMsAMualm2hMiKSXFreYNQF8bxwB LStcWvZkO8MAAeoL+SiRHfxV2wuyB50vEchDfdTVUsyPE8ny2nTGya8igVmtN7/h +aYebE+QbI450/eMtvOSUhdblMrO4A9JPYgQD3heMPmIZvkqWmDzFvP2F0VmLPz9 fdY5Xv3Pk5I=xQ5I -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.