Bugzilla – Bug 1215510
VUL-0: CVE-2023-43617: croc: sender and receiver may divulge parts of this secret to an untrusted Relay
Last modified: 2023-09-20 09:15:07 UTC
CVE-2023-43617 An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-43617 https://www.cve.org/CVERecord?id=CVE-2023-43617 http://www.openwall.com/lists/oss-security/2023/09/08/2 https://github.com/schollz/croc/issues/596
Please submit to the following code streams: network croc openSUSE:Backports:SLE-15-SP6 croc