cbcvebase.
CVE-2023-1672
published 2023-07-11

CVE-2023-1672: A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys…

medium5.3CVSS 3.1
AVAACHPRNUINSUCHINAN
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiantang< tang 11-2+deb12u1 (bookworm)tang 11-2+deb12u1 (bookworm)
fedoraprojectfedora
msrccbl2_tang_14-1_on_cbl_mariner_2.0
redhatenterprise_linux
redhatenterprise_linux
tang_projecttang< 1414
tang_projecttang>= 0 < 8-3+deb11u28-3+deb11u2
tang_projecttang>= 0 < 11-2+deb12u111-2+deb12u1
tang_projecttang>= 0 < 14-114-1
tang_projecttang>= 0 < 14-114-1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.3MEDIUM