[Bug 1217428] New: VUL-0: CVE-2023-6258: pkcs11-provider: Side-channel proofing PKCS#1 1.5 paths

https://bugzilla.suse.com/show_bug.cgi?id=1217428 Bug ID: 1217428 Summary: VUL-0: CVE-2023-6258: pkcs11-provider: Side-channel proofing PKCS#1 1.5 paths Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/385844/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: luca.boccassi@gmail.com Reporter: smash_bz@suse.de QA Contact: security-team@suse.de CC: thomas.leroy@suse.com Target Milestone: --- Found By: Security Response Team Blocker: --- Side-channel proofing PKCS#1 1.5 paths (Marvin) Ref: https://github.com/latchset/pkcs11-provider/pull/308 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-6258 -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1217428 https://bugzilla.suse.com/show_bug.cgi?id=1217428#c1 --- Comment #1 from Thomas Leroy <thomas.leroy@suse.com> --- PR not merged yet. openSUSE:Factory affected -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1217428 Maintenance Automation <maint-coord+maintenance-robot@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1217428 Lucas Mulling <lucas.mulling@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|luca.boccassi@gmail.com |lucas.mulling@suse.com CC| |lucas.mulling@suse.com -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1217428 https://bugzilla.suse.com/show_bug.cgi?id=1217428#c2 Lucas Mulling <lucas.mulling@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |IN_PROGRESS --- Comment #2 from Lucas Mulling <lucas.mulling@suse.com> --- Factory is now on 0.6, I could not find any affected version < 0.3. -- You are receiving this mail because: You are on the CC list for the bug.

https://bugzilla.suse.com/show_bug.cgi?id=1217428 Lucas Mulling <lucas.mulling@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|lucas.mulling@suse.com |security-team@suse.de -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com