Update to 0.080 Fix CVE-2019-17362 in bundled libtomcrypt. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-b4b9b38f23 2023-12-14 01:51:57.490278 -------------------------------------------------------------------------------- Name : perl-CryptX Product : Fedora 38 Version : 0.080 Release : 1.fc38 URL : https://metacpan.org/dist/CryptX Summary : Cryptographic toolkit Description : This Perl library provides a cryptography based on LibTomCrypt library. -------------------------------------------------------------------------------- Update Information: Update to 0.080 Fix CVE-2019-17362 in bundled libtomcrypt -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 4 2023 Xavier Bachelot - 0.080-1 - Update to 0.080 (RHBZ#2242102) * Mon Oct 2 2023 Xavier Bachelot - 0.079-1 - Update to 0.079 (RHBZ#2241629) - Fix CVE-2019-17362 in bundled libtomcrypt - Add upstream patch to fix tests with Math::BigInt 1.999840+ (RHBZ#2240587) * Fri Aug 25 2023 Xavier Bachelot - 0.078-4 - Don't Requires: perl(Math::BigFloat) for tests subpackage on EL7 (RHBZ#2234802) * Thu Jul 20 2023 Fedora Release Engineering - 0.078-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue Jul 11 2023 Jitka Plesnikova - 0.078-2 - Perl 5.38 rebuild * Thu May 11 2023 Xavier Bachelot - 0.078-1 - Update to 0.078 (RHBZ#2120043) - Convert license to SPDX -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b4b9b38f23' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 0.080 Fix CVE-2019-17362 in bundled libtomcrypt. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-1f0ac1260e 2023-12-14 01:30:12.883518 -------------------------------------------------------------------------------- Name : perl-CryptX Product : Fedora 39 Version : 0.080 Release : 1.fc39 URL : https://metacpan.org/dist/CryptX Summary : Cryptographic toolkit Description : This Perl library provides a cryptography based on LibTomCrypt library. -------------------------------------------------------------------------------- Update Information: Update to 0.080 Fix CVE-2019-17362 in bundled libtomcrypt -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 4 2023 Xavier Bachelot - 0.080-1 - Update to 0.080 (RHBZ#2242102) * Mon Oct 2 2023 Xavier Bachelot - 0.079-1 - Update to 0.079 (RHBZ#2241629) - Fix CVE-2019-17362 in bundled libtomcrypt - Add upstream patch to fix tests with Math::BigInt 1.999840+ (RHBZ#2240587) * Fri Aug 25 2023 Xavier Bachelot - 0.078-4 - Don't Requires: perl(Math::BigFloat) for tests subpackage on EL7 (RHBZ#2234802) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1f0ac1260e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Updated libtomcrypt packages fix security vulnerability: Improper detection of invalid UTF-8 sequences that could have led to DoS or information disclosure via crafted DER-encoded data (CVE-2019-17362). . MGASA-2020-0028 - Updated libtomcrypt packages fix security vulnerability Publication date: 11 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0028.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-17362 Updated libtomcrypt packages fix security vulnerability: Improper detection of invalid UTF-8 sequences that could have led to DoS or information disclosure via crafted DER-encoded data (CVE-2019-17362). References: - https://bugs.mageia.org/show_bug.cgi?id=25808 - - https://www.cve.org/CVERecord?id=CVE-2019-17362 SRPMS: - 7/core/libtomcrypt-1.18.2-2.1.mga7 . Revised libtomcrypt modules tackle flaws in UTF-8 detection that pose threats of DoS and sensitive data exposure.. libtomcrypt Security Update, Mageia CVE Fix, UTF-8 Security Issue. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libtomcrypt ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:3095-1 Rating: moderate References: #1153433 Cross-References: CVE-2019-17362 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Desktop 12-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libtomcrypt fixes the following issues: - CVE-2019-17362: Fixed an improper detection of invalid UTF-8 sequences that could have led to DoS or information disclosure via crafted DER-encoded data (bsc#1153433). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2019-3095=1 - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2019-3095=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-3095=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libtomcrypt-debugsource-1.17-3.3.1 libtomcrypt0-1.17-3.3.1 libtomcrypt0-debuginfo-1.17-3.3.1 - SUSE Linux Enterprise Workstation Extension 12-SP4 (x86_64): libtomcrypt-debugsource-1.17-3.3.1 libtomcrypt0-1.17-3.3.1 libtomcrypt0-debuginfo-1.17-3.3.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): libtomcrypt-debugsource-1.17-3.3.1 libtomcrypt0-1.17-3.3.1 libtomcrypt0-debuginfo-1.17-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-17362.html https://bugzilla.suse.com/1153433 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libtomcrypt ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2514-1 Rating: moderate References: #1153433 Cross-References: CVE-2019-17362 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libtomcrypt fixes the following issue: CVE-2019-17362: Fixed an improper detection of invalid UTF-8 sequences that could have led to DoS or information disclosure via crafted DER-encoded data (bsc#1153433). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2514=1 Package List: - openSUSE Leap 15.1 (x86_64): libtomcrypt-debugsource-1.17-lp151.3.3.1 libtomcrypt-devel-1.17-lp151.3.3.1 libtomcrypt-examples-1.17-lp151.3.3.1 libtomcrypt0-1.17-lp151.3.3.1 libtomcrypt0-debuginfo-1.17-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-17362.html https://bugzilla.suse.com/1153433 -- . openSUSE Security Alert: libtomcrypt addresses faulty UTF-8 validation causing potential denial of service vulnerabilities. Immediate action advised.. openSUSE Security Update, libtomcrypt DoS fix, UTF-8 vulnerability patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libtomcrypt ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2454-1 Rating: moderate References: #1153433 Cross-References: CVE-2019-17362 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libtomcrypt fixes the following issue: CVE-2019-17362: Fixed an improper detection of invalid UTF-8 sequences that could have led to DoS or information disclosure via crafted DER-encoded data (bsc#1153433). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-2454=1 Package List: - openSUSE Leap 15.0 (x86_64): libtomcrypt-debugsource-1.17-lp150.2.3.1 libtomcrypt-devel-1.17-lp150.2.3.1 libtomcrypt-examples-1.17-lp150.2.3.1 libtomcrypt0-1.17-lp150.2.3.1 libtomcrypt0-debuginfo-1.17-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2019-17362.html https://bugzilla.suse.com/1153433 -- . openSUSE has issued a security patch for libtomcrypt, addressing a moderate denial-of-service vulnerability and a potential information leak.. openSUSE, libtomcrypt, security patch, software update. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libtomcrypt ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2808-1 Rating: moderate References: #1153433 Cross-References: CVE-2019-17362 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libtomcrypt fixes the following issue: CVE-2019-17362: Fixed an improper detection of invalid UTF-8 sequences that could have led to DoS or information disclosure via crafted DER-encoded data (bsc#1153433). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-2808=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-2808=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): libtomcrypt-debugsource-1.17-3.3.1 libtomcrypt-devel-1.17-3.3.1 libtomcrypt-examples-1.17-3.3.1 libtomcrypt0-1.17-3.3.1 libtomcrypt0-debuginfo-1.17-3.3.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): libtomcrypt-debugsource-1.17-3.3.1 libtomcrypt-devel-1.17-3.3.1 libtomcrypt-examples-1.17-3.3.1 libtomcrypt0-1.17-3.3.1 libtomcrypt0-debuginfo-1.17-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-17362.html https://bugzilla.suse.com/1153433 _______________________________________________ sle-security-updates mailing list
It was discovered that there was a denial of service vulnerability in the libtomcrypt cryptographic library. An out-of-bounds read and crash could occur via carefully-crafted . Package : libtomcrypt Version : 1.17-6+deb8u1 CVE ID : CVE-2019-17362 It was discovered that there was a denial of service vulnerability in the libtomcrypt cryptographic library. An out-of-bounds read and crash could occur via carefully-crafted "DER" encoded data (eg. by importing an X.509 certificate). For Debian 8 "Jessie", this issue has been fixed in libtomcrypt version 1.17-6+deb8u1. We recommend that you upgrade your libtomcrypt packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.