USN-6489-1: Tang vulnerability
20 November 2023
Tang could allow unintended access to secret keys.
Releases
Packages
- tang - network-based cryptographic binding server
Details
Brian McDermott discovered that Tang incorrectly handled permissions when
creating/rotating keys. A local attacker could possibly use this issue to
read the keys.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.04
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
tang
-
6-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.