UbuntuUpdates.org

Package "tang"

Name: tang

Description:

network-based cryptographic binding server

Latest version: 7-1ubuntu0.2
Release: focal (20.04)
Level: security
Repository: universe
Homepage: https://github.com/latchset/tang

Links


Download "tang"


Other versions of "tang" in Focal

Repository Area Version
base universe 7-1build1
updates universe 7-1ubuntu0.2

Changelog

Version: 7-1ubuntu0.2 2023-11-20 17:06:54 UTC

  tang (7-1ubuntu0.2) focal-security; urgency=medium

  * SECURITY UPDATE: race condition when creating and rotating keys
    - debian/patches/CVE-2023-1672.patch: Assert restrictive permissions
      on tang's key directory
    - CVE-2023-1672

 -- Jorge Sancho Larraz <email address hidden> Mon, 20 Nov 2023 11:32:48 +0100

CVE-2023-1672 A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang pri



About   -   Send Feedback to @ubuntu_updates