Tang could allow unintended access to secret keys.. ========================================================================== Ubuntu Security Notice USN-6489-1 November 20, 2023 tang vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Tang could allow unintended access to secret keys. Software Description: - tang: network-based cryptographic binding server Details: Brian McDermott discovered that Tang incorrectly handled permissions when creating/rotating keys. A local attacker could possibly use this issue to read the keys. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: tang-common 11-2ubuntu0.1 Ubuntu 22.04 LTS: tang-common 11-1ubuntu0.1 Ubuntu 20.04 LTS: tang 7-1ubuntu0.2 Ubuntu 18.04 LTS (Available with Ubuntu Pro): tang 6-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6489-1 CVE-2023-1672 Package Information: https://launchpad.net/ubuntu/+source/tang/11-2ubuntu0.1 https://launchpad.net/ubuntu/+source/tang/11-1ubuntu0.1 https://launchpad.net/ubuntu/+source/tang/7-1ubuntu0.2 . The Ubuntu Security Notice USN-6490-1 highlights a critical flaw in the curl library, which may permit unauthorized exposure of sensitive data.. Ubuntu Security,Tang Vulnerability,Access Control,Key Management. . Severity: Critical. LinuxSecurity.com Team
It was discovered that there was a race condition in Tang, a network-based cryptographic binding server. This flaw resulted in a small time window whereby newly-generated private keys were readable by other processes on the same machine. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3648-1
Fixes CVE-2023-1672. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-3e84bba241 2023-06-23 01:00:55.101941 --------------------------------------------------------------------------------Name : tang Product : Fedora 38 Version : 14 Release : 1.fc38 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Fixes CVE-2023-1672 --------------------------------------------------------------------------------ChangeLog: * Wed Jun 14 2023 Sergio Arroutbi - 14-1 - New upstream release - v14 Resolves: rhbz#2180990 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180999 - CVE-2023-1672 tang: Race condition exists in the key generation and rotation functionality https://bugzilla.redhat.com/show_bug.cgi?id=2180999 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-3e84bba241' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fixes CVE-2023-1672. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-eb9bec6e8c 2023-06-23 01:00:50.019322 --------------------------------------------------------------------------------Name : tang Product : Fedora 37 Version : 14 Release : 1.fc37 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Fixes CVE-2023-1672 --------------------------------------------------------------------------------ChangeLog: * Wed Jun 14 2023 Sergio Arroutbi - 14-1 - New upstream release - v14 Resolves: rhbz#2180990 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180999 - CVE-2023-1672 tang: Race condition exists in the key generation and rotation functionality https://bugzilla.redhat.com/show_bug.cgi?id=2180999 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-eb9bec6e8c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-4076. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-aa1d373ed0 2021-12-23 01:25:07.749353 --------------------------------------------------------------------------------Name : tang Product : Fedora 34 Version : 11 Release : 1.fc34 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-4076 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 14 2021 Sergio Correia - 11-1 - New upstream release - v11. Resolves: CVE-2021-4076 --------------------------------------------------------------------------------References: [ 1 ] Bug #2029814 - CVE-2021-4076 tang: private key leak https://bugzilla.redhat.com/show_bug.cgi?id=2029814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-aa1d373ed0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2021-4076. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-1fe489496f 2021-12-23 00:39:33.251213 --------------------------------------------------------------------------------Name : tang Product : Fedora 35 Version : 11 Release : 1.fc35 URL : https://github.com/latchset/tang Summary : Network Presence Binding Daemon Description : Tang is a small daemon for binding data to the presence of a third party. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-4076 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 14 2021 Sergio Correia - 11-1 - New upstream release - v11. Resolves: CVE-2021-4076 --------------------------------------------------------------------------------References: [ 1 ] Bug #2029814 - CVE-2021-4076 tang: private key leak https://bugzilla.redhat.com/show_bug.cgi?id=2029814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-1fe489496f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A flaw was discovered in tang, a network-based cryptographic binding server, which could result in leak of private keys. For the stable distribution (bullseye), this problem has been fixed in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5025-1
Get the latest Linux and open source security news straight to your inbox.