[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3648-1] tang security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3648-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                           Chris Lamb
November 07, 2023                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : tang
Version        : 7-1+deb10u2
CVE ID         : CVE-2023-1672
Debian Bug     : 1038119

It was discovered that there was a race condition in Tang, a
network-based cryptographic binding server. This flaw resulted in a
small time window whereby newly-generated private keys were readable
by other processes on the same machine.

For Debian 10 buster, this problem has been fixed in version
7-1+deb10u2.

We recommend that you upgrade your tang packages.

For the detailed security status of tang please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/tang

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmVKKB8ACgkQHpU+J9Qx
Hli19A/+MmBUHkk71l/TpW3DaUmSZDus4lMeMB+2P01yKnd3qxVEHjZzYvWPR9cA
BCz5FQrRsOe5+ZfWyC7CSpuWPOcmsBuxkEtGq8OwAaTuVK3sWN4ZGf3+yADVT1OI
7VhDFtsNeHJO8NdrVOJ14AsnOx1erZ1rp+qE9CXb/GezUMAnT4YPvBmlbIyaVBxO
yd9bVYGHBmvBM+XMnnut3MfRAMxXFkPzUO6OzbElPMB7F7cSWEhl546XyaBT4gI3
m3eUc+xpriAcQoV5YOtfgo5MP33Qw9hPrevHUOn/WAw9JnlTwj5TueA3OFhqL6zO
NGuQa2ZVy5zI/TIO2H7gRHbbQqsqWx7i1BrGbtbxabKAh9QMbj99WBK21OAAC34r
vl11RwGugL5pvr2AhwJuSMw+Mz4UqX1JpOQg5KZ6uHJyPIcgXKg/r/YgOgCyaYOp
E2u1FPqbLYuYRZt49Zl3aDb3IKWe3f++SR/S6L6a1gRYV1rihHtqmMQj1XVA+gaC
2ft9XS5yMvEipQJoTE6DrK9Bur5LM4wWSGy2m8Q8lrrIEzBvxVSHn3Mjmtvn80Zt
RveTdC8L9kbCoireiGXL4zZw7EhJ7OHpL+2Aivqju2L2JNxIK04YokUzZCXo+AC/
c+bfONCdatBD0lAd0Me+EUwgnrsVmu37EeYGYDh8OnB/JW2qucM=
=vWkc
-----END PGP SIGNATURE-----


Reply to: