QID 357188
Date Published: 2024-02-20
QID 357188: Amazon Linux Security Advisory for nss-softokn : AL2012-2024-487
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2023-5388:
It was discovered that the numerical library used in NSS for RSA cryptography leaks information whether high order bits of the RSA decryption result are zero. This information can be used to mount a Bleichenbacher or Manger like attack against all RSA decryption operations. As the leak happens before any padding operations, it affects all padding modes: PKCS#1 v1.5, OAEP, and RSASVP. Both API level calls and TLS server operation are affected.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 357188
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2024-487 | Amazon Linux Bare Metal |
|