Thursday, May 30, 2024

[USN-6800-1] browserify-sign vulnerability

-----BEGIN PGP SIGNATURE-----

wsD5BAABCAAjFiEELRdhz3KY7FGicMD8Vjg+NdFTuLIFAmZYhMcFAwAAAAAACgkQVjg+NdFTuLJ3
Igv+JIaooE1DEwS/l3S2G/SNDwAm/lmL/NS3h8FGVryyQNsOGPMsq59rUYi9+Igl9yaUo14tCAta
UbXoAb9wiXVGLRiV+fQRAFNwOId47QvSVQSRWy4bJTPmw7IAhFcAi4a0cdoOFxLAQE+UMOKxysUF
cAIXGtE+CZEastcEmgfZsR8mRcAhM504lCFGxajwAK1KffcyTTmZscZBPIp81Ws6JDjLqzX8VftG
CcwOFsww1oPGoQGJbGF2+MaHSsUvVVHcvzaNaVM22vOyfGvebaMG1S/MrdwkCzYJyfIdg9QT3yD9
pR9KP5oVYzGbyLeM/dELsTrDjkj737zO/1ZAhhUJR/aKgYIybPdqiYrEgI56Tor770IOUSLC8lqt
NeOfd1rEo3pKrsLH0C/d/j531bVL0zpJTLau3LgvILznalJdy09j2nT6YvDP11p5QKjK9UI180Ax
JrL5tn8LDSo7LLLrvWPrSJae6ua+37nxKaoOfdbyu4XNKDkTx/XzIVk29gbY
=4MDO
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-6800-1
May 30, 2024

node-browserify-sign vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

browserify-sign could allow unintended access if it opened a specially crafted
file.

Software Description:
- node-browserify-sign: createSign and createVerify in your browser

Details:

It was discovered that browserify-sign incorrectly handled an upper bound check
in signature verification. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to perform a signature forgery attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10
node-browserify-sign 4.2.1-3ubuntu0.1

Ubuntu 22.04 LTS
node-browserify-sign 4.2.1-2ubuntu0.1

Ubuntu 20.04 LTS
node-browserify-sign 4.0.4-2ubuntu0.20.04.1

Ubuntu 18.04 LTS
node-browserify-sign 4.0.4-2ubuntu0.18.04.1~esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-6800-1
CVE-2023-46234

Package Information:
https://launchpad.net/ubuntu/+source/node-browserify-sign/4.2.1-3ubuntu0.1
https://launchpad.net/ubuntu/+source/node-browserify-sign/4.2.1-2ubuntu0.1
https://launchpad.net/ubuntu/+source/node-browserify-sign/4.0.4-2ubuntu0.20.04.1

No comments:

Post a Comment