SB2022112983 - Fedora EPEL 9 update for botan2



SB2022112983 - Fedora EPEL 9 update for botan2

Published: November 29, 2022

Security Bulletin ID SB2022112983
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Certificate Validation (CVE-ID: CVE-2022-43705)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to spoof certificate revocation status and bypass revocation checks.

The vulnerability exists due to improper certificate validation in OCSP response verification when processing embedded OCSP responder certificates. A remote privileged user can spoof a crafted OCSP response to spoof certificate revocation status and bypass revocation checks.

Only deployments that rely on OCSP for certificate revocation checks are affected. The issue can be exploited in scenarios such as OCSP stapling.


Remediation

Install update from vendor's website.