ALT-PU-2024-14971-1
Package jose updated to version 14-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
Published: 2024-03-20
BDU:2024-02461
Уязвимость модуля языка С для подписи и шифрования объектов JSON latchset Jose, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2024-03-20
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-50967
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
References:
- https://github.com/latchset/jose
- https://github.com/latchset/jose
- https://github.com/P3ngu1nW/CVE_Request/blob/main/latch-jose.md
- https://github.com/P3ngu1nW/CVE_Request/blob/main/latch-jose.md
- FEDORA-2024-f98bdff610
- FEDORA-2024-f98bdff610
- FEDORA-2024-a94b67a7b2
- FEDORA-2024-a94b67a7b2
- FEDORA-2024-2cface5aba
- FEDORA-2024-2cface5aba