MGASA-2021-0492 - Updated opencryptoki packages fix security vulnerability

Publication date: 27 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0492.html
Type: security
Affected Mageia releases: 8

It was discovered that openCryptoki incorrectly handled certain EC keys.
An attacker could possibly use this issue to cause a invalid curve attack.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29328
- https://ubuntu.com/security/notices/USN-5031-1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FLP3UNIVGYENSFGVADMQ2IYP4A3TDYJC/

SRPMS:
- 8/core/opencryptoki-3.15.1-1.1.mga8

Mageia 2021-0492: opencryptoki security update

It was discovered that openCryptoki incorrectly handled certain EC keys

Summary

It was discovered that openCryptoki incorrectly handled certain EC keys. An attacker could possibly use this issue to cause a invalid curve attack. References: - https://bugs.mageia.org/show_bug.cgi?id=29328

References

- https://bugs.mageia.org/show_bug.cgi?id=29328

- https://ubuntu.com/security/notices/USN-5031-1

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/FLP3UNIVGYENSFGVADMQ2IYP4A3TDYJC/

Resolution

MGASA-2021-0492 - Updated opencryptoki packages fix security vulnerability

SRPMS

- 8/core/opencryptoki-3.15.1-1.1.mga8

Severity
Publication date: 27 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0492.html
Type: security

Related News