Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:3230-1

Опубликовано: 08 авг. 2023
Источник: suse-cvrf

Описание

Security update for cjose

This update for cjose fixes the following issues:

  • CVE-2023-37464: Fixed AES GCM decryption uses the Tag length from the actual Authentication Tag (bsc#1213385).

Список пакетов

SUSE Enterprise Storage 7
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Enterprise Storage 7.1
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Module for Server Applications 15 SP4
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Module for Server Applications 15 SP5
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Real Time 15 SP3
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Server 15 SP1-LTSS
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Server 15 SP2-LTSS
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Server 15 SP3-LTSS
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Manager Proxy 4.2
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
SUSE Manager Server 4.2
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
openSUSE Leap 15.4
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1
openSUSE Leap 15.5
libcjose-devel-0.6.1-150100.4.6.1
libcjose0-0.6.1-150100.4.6.1

Описание

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octets must be applied. Therefore this bug allows an attacker to provide a truncated Authentication Tag and to modify the JWE accordingly. Users should upgrade to a version >= 0.6.2.2. Users unable to upgrade should avoid using AES GCM encryption and replace it with another encryption algorithm (e.g. AES CBC).


Затронутые продукты
SUSE Enterprise Storage 7.1:libcjose-devel-0.6.1-150100.4.6.1
SUSE Enterprise Storage 7.1:libcjose0-0.6.1-150100.4.6.1
SUSE Enterprise Storage 7:libcjose-devel-0.6.1-150100.4.6.1
SUSE Enterprise Storage 7:libcjose0-0.6.1-150100.4.6.1

Ссылки
Уязвимость SUSE-SU-2023:3230-1