ALAS-2023-1858

Related Vulnerabilities: CVE-2023-4421  

new tlsfuzzer code can still detect timing issues in RSA operations (CVE-2023-4421)

ALAS-2023-1858


Amazon Linux 1 Security Advisory: ALAS-2023-1858
Advisory Release Date: 2023-10-12 15:48 Pacific
Advisory Updated Date: 2023-10-24 21:38 Pacific
Severity: Medium

Issue Overview:

new tlsfuzzer code can still detect timing issues in RSA operations (CVE-2023-4421)


Affected Packages:

nss-softokn


Issue Correction:
Run yum update nss-softokn to update your system.

New Packages:
i686:
    nss-softokn-3.53.1-6.48.amzn1.i686
    nss-softokn-freebl-devel-3.53.1-6.48.amzn1.i686
    nss-softokn-debuginfo-3.53.1-6.48.amzn1.i686
    nss-softokn-devel-3.53.1-6.48.amzn1.i686
    nss-softokn-freebl-3.53.1-6.48.amzn1.i686

src:
    nss-softokn-3.53.1-6.48.amzn1.src

x86_64:
    nss-softokn-3.53.1-6.48.amzn1.x86_64
    nss-softokn-devel-3.53.1-6.48.amzn1.x86_64
    nss-softokn-freebl-devel-3.53.1-6.48.amzn1.x86_64
    nss-softokn-debuginfo-3.53.1-6.48.amzn1.x86_64
    nss-softokn-freebl-3.53.1-6.48.amzn1.x86_64