Bug 1212254 (CVE-2023-29480) - VUL-0: CVE-2023-29480: rnp: secret keys may remain unlocked after use
Summary: VUL-0: CVE-2023-29480: rnp: secret keys may remain unlocked after use
Status: RESOLVED FIXED
Alias: CVE-2023-29480
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security (show other bugs)
Version: Current
Hardware: Other Other
: P5 - None : Major (vote)
Target Milestone: ---
Assignee: Andreas Stieger
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-06-12 17:23 UTC by Andreas Stieger
Modified: 2023-06-12 17:29 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2023-06-12 17:23:39 UTC
Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-29480
https://www.rnpgp.org/blog/2023-04-13-rnp-release-0-16-3/
https://github.com/advisories/GHSA-rr9h-qqwq-gm72
Comment 1 Andreas Stieger 2023-06-12 17:29:08 UTC
https://build.opensuse.org/request/show/1092656