QID 356342
Date Published: 2023-10-18
QID 356342: Amazon Linux Security Advisory for ca-certificates : AL2012-2023-445
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2023-37920:
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 356342
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-445 | Amazon Linux Bare Metal |
|