Please patch CVEs for package opencryptoki version 3.14.0 INFO (CVEs are): opencryptoki 3.14.0 cves found CVE-2021-3798 Desc: A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is created via C_CreateObject, nor when C_DeriveKey is used with ECDH public data. This may allow a malicious user to extract the private key by performing an invalid curve attack. Link: https://nvd.nist.gov/vuln/detail/CVE-2021-3798 Severity: MEDIUM
Не затрагивает нашу версию.
Secteam Verified
*** This bug has been marked as a duplicate of bug 13912 ***