Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1672

Опубликовано: 11 июл. 2023
Источник: debian

Описание

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tangfixed14-1package
tangfixed11-2+deb12u1bookwormpackage
tangfixed8-3+deb11u2bullseyepackage

Примечания

  • Fixed by: https://github.com/latchset/tang/commit/8dbbed10870378f1b2c3cf3df2ea7edca7617096

  • https://census-labs.com/news/2023/06/15/race-tang/

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

CVSS3: 5.3
redhat
больше 2 лет назад

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

CVSS3: 5.3
nvd
больше 2 лет назад

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

CVSS3: 5.3
msrc
больше 2 лет назад

Race condition exists in the key generation and rotation functionality

CVSS3: 5.3
github
больше 2 лет назад

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.