[USN-5031-1] openCryptoki vulnerability
Leonidas S. Barbosa
leo.barbosa at canonical.com
Wed Aug 4 17:09:56 UTC 2021
Ubuntu Security Notice USN-5031-1
August 04, 2021
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 21.04
openCryptoki could be made to allow invalid curve attacks if it received a specially
- opencryptoki: PKCS#11 implementation (daemon)
It was discovered that openCryptoki incorrectly handled certain EC keys.
An attacker could possibly use this issue to cause a invalid curve attack.
The problem can be corrected by updating your system to the following
In general, a standard system update will make all the necessary changes.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the ubuntu-security-announce