The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-0108 https://linux.oracle.com/errata/ELSA-2024-0108.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nspr-4.35.0-4.el9_3.i686.rpm nspr-4.35.0-4.el9_3.x86_64.rpm nspr-devel-4.35.0-4.el9_3.i686.rpm nspr-devel-4.35.0-4.el9_3.x86_64.rpm nss-3.90.0-4.el9_3.i686.rpm nss-3.90.0-4.el9_3.x86_64.rpm nss-devel-3.90.0-4.el9_3.i686.rpm nss-devel-3.90.0-4.el9_3.x86_64.rpm nss-softokn-3.90.0-4.el9_3.i686.rpm nss-softokn-3.90.0-4.el9_3.x86_64.rpm nss-softokn-devel-3.90.0-4.el9_3.i686.rpm nss-softokn-devel-3.90.0-4.el9_3.x86_64.rpm nss-softokn-freebl-3.90.0-4.el9_3.i686.rpm nss-softokn-freebl-3.90.0-4.el9_3.x86_64.rpm nss-softokn-freebl-devel-3.90.0-4.el9_3.i686.rpm nss-softokn-freebl-devel-3.90.0-4.el9_3.x86_64.rpm nss-sysinit-3.90.0-4.el9_3.x86_64.rpm nss-tools-3.90.0-4.el9_3.x86_64.rpm nss-util-3.90.0-4.el9_3.i686.rpm nss-util-3.90.0-4.el9_3.x86_64.rpm nss-util-devel-3.90.0-4.el9_3.i686.rpm nss-util-devel-3.90.0-4.el9_3.x86_64.rpm aarch64: nspr-4.35.0-4.el9_3.aarch64.rpm nspr-devel-4.35.0-4.el9_3.aarch64.rpm nss-3.90.0-4.el9_3.aarch64.rpm nss-devel-3.90.0-4.el9_3.aarch64.rpm nss-softokn-3.90.0-4.el9_3.aarch64.rpm nss-softokn-devel-3.90.0-4.el9_3.aarch64.rpm nss-softokn-freebl-3.90.0-4.el9_3.aarch64.rpm nss-softokn-freebl-devel-3.90.0-4.el9_3.aarch64.rpm nss-sysinit-3.90.0-4.el9_3.aarch64.rpm nss-tools-3.90.0-4.el9_3.aarch64.rpm nss-util-3.90.0-4.el9_3.aarch64.rpm nss-util-devel-3.90.0-4.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//nss-3.90.0-4.el9_3.src.rpm Related CVEs: CVE-2023-5388 Description of changes: [3.90.0-4] - CVE-2023-5388 nss: timing attack against RSA decryption. Make the final blinding multmod constant time. _______________________________________________ El-errata mailing list
Timing side channel in the RSA decryption implementation of the GNU TLS library. (CVE-2023-0361) References: - https://bugs.mageia.org/show_bug.cgi?id=31558 . MGASA-2023-0067 - Updated gnutls packages fix security vulnerability Publication date: 27 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0067.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-0361 Timing side channel in the RSA decryption implementation of the GNU TLS library. (CVE-2023-0361) References: - https://bugs.mageia.org/show_bug.cgi?id=31558 - https://lists.debian.org/debian-security-announce/2023/msg00038.html - https://lists.debian.org/debian-lts-announce/2023/02/msg00015.html - https://www.cve.org/CVERecord?id=CVE-2023-0361 SRPMS: - 8/core/gnutls-3.6.15-3.4.mga8 . The latest gnutls updates in Mageia resolve a critical timing attack vulnerability connected to RSA decryption. Find out more here.. timing Attack, GnuTLS Update, Mageia Security Fix, RSA Decryption Issue. . Severity: Critical. LinuxSecurity.com Team
Bleichenbacher timing attacks in the RSA decryption API (CVE-2020-25657) References: - https://bugs.mageia.org/show_bug.cgi?id=30661 - https://lists.suse.com/pipermail/sle-security-updates/2022-July/011631.html . MGASA-2022-0274 - Updated python-m2crypto packages fix security vulnerability Publication date: 05 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0274.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-25657 Bleichenbacher timing attacks in the RSA decryption API (CVE-2020-25657) References: - https://bugs.mageia.org/show_bug.cgi?id=30661 - https://lists.suse.com/pipermail/sle-security-updates/2022-July/011631.html - - https://www.cve.org/CVERecord?id=CVE-2020-25657 SRPMS: - 8/core/python-m2crypto-0.38.0-4.mga8 . Recent updates to the python-m2crypto packages have effectively mitigated the Bleichenbacher timing attacks impacting the RSA decryption API on Mageia 8.. Bleichenbacher Attack, Python Security Update, Mageia Advisory. . LinuxSecurity.com Team
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server. (CVE-2018-16868) . MGASA-2019-0103 - Updated gnutls packages fix security vulnerability Publication date: 07 Mar 2019 URL: https://advisories.mageia.org/MGASA-2019-0103.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-16868 A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server. (CVE-2018-16868) References: - https://bugs.mageia.org/show_bug.cgi?id=24066 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.