Lucene search

K
mageiaGentoo FoundationMGASA-2023-0273
HistorySep 30, 2023 - 10:15 p.m.

Updated quictls packages fix security vulnerabilities

2023-09-3022:15:40
Gentoo Foundation
advisories.mageia.org
32
quictls
packages
security
vulnerabilities
aes-siv
implementation
associated data
dh keys
parameters
q parameter value
unix

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.005

Percentile

77.2%

The updated packages fix security vulnerabilities: AES-SIV implementation ignores empty associated data entries. (CVE-2023-2975) Excessive time spent checking DH keys and parameters. (CVE-2023-3446) Excessive time spent checking DH q parameter value. (CVE-2023-3817)

OSVersionArchitecturePackageVersionFilename
Mageia9noarchquictls< 3.0.10-1quictls-3.0.10-1.mga9

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS

0.005

Percentile

77.2%