Ubuntu Security Update USN-6307-1: JOSE for C/C++ vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,925
Reaction score
75
Credits
-1,257
It was discovered that JOSE for C/C++ AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. An attacker could use this to cause a denial of service (system crash) or might expose sensitive information.

Continue reading...
 


Follow Linux.org

Staff online


Top