Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1672

Опубликовано: 11 июл. 2023
Источник: debian
EPSS Низкий

Описание

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tangfixed14-1package
tangfixed11-2+deb12u1bookwormpackage
tangfixed8-3+deb11u2bullseyepackage

Примечания

  • Fixed by: https://github.com/latchset/tang/commit/8dbbed10870378f1b2c3cf3df2ea7edca7617096

  • https://census-labs.com/news/2023/06/15/race-tang/

EPSS

Процентиль: 6%
0.00028
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

CVSS3: 5.3
redhat
около 2 лет назад

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

CVSS3: 5.3
nvd
около 2 лет назад

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

CVSS3: 5.3
github
около 2 лет назад

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

oracle-oval
почти 2 года назад

ELSA-2023-7022: tang security and bug fix update (MODERATE)

EPSS

Процентиль: 6%
0.00028
Низкий