ALAS2-2023-2304

Related Vulnerabilities: CVE-2022-2393  

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content. (CVE-2022-2393)

ALAS2-2023-2304


Amazon Linux 2 Security Advisory: ALAS-2023-2304
Advisory Release Date: 2023-10-12 15:09 Pacific
Advisory Updated Date: 2023-10-19 23:41 Pacific
Severity: Medium

Issue Overview:

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content. (CVE-2022-2393)


Affected Packages:

pki-core


Issue Correction:
Run yum update pki-core to update your system.

New Packages:
aarch64:
    pki-symkey-10.5.18-27.amzn2.0.1.aarch64
    pki-tools-10.5.18-27.amzn2.0.1.aarch64
    pki-core-debuginfo-10.5.18-27.amzn2.0.1.aarch64

i686:
    pki-symkey-10.5.18-27.amzn2.0.1.i686
    pki-tools-10.5.18-27.amzn2.0.1.i686
    pki-core-debuginfo-10.5.18-27.amzn2.0.1.i686

noarch:
    pki-base-10.5.18-27.amzn2.0.1.noarch
    pki-base-java-10.5.18-27.amzn2.0.1.noarch
    pki-server-10.5.18-27.amzn2.0.1.noarch
    pki-ca-10.5.18-27.amzn2.0.1.noarch
    pki-kra-10.5.18-27.amzn2.0.1.noarch
    pki-javadoc-10.5.18-27.amzn2.0.1.noarch

src:
    pki-core-10.5.18-27.amzn2.0.1.src

x86_64:
    pki-symkey-10.5.18-27.amzn2.0.1.x86_64
    pki-tools-10.5.18-27.amzn2.0.1.x86_64
    pki-core-debuginfo-10.5.18-27.amzn2.0.1.x86_64