- Package:
- src:libjwt
- Source:
- src:libjwt
- Submitter:
- Moritz Mühlenhoff
- Date:
- 2024-03-03 13:21:10 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for libjwt. CVE-2024-25189[0]: | libjwt 1.15.3 uses strcmp (which is not constant time) to verify | authentication, which makes it easier to bypass authentication via a | timing side channel. The report is https://github.com/P3ngu1nW/CVE_Request/blob/main/benmcollins%3Alibjwt.md but it doesn't seem to have been reported upstream yet. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2024-25189 https://www.cve.org/CVERecord?id=CVE-2024-25189 Please adjust the affected versions in the BTS as needed.
Hi Moritz, thanks for the bug. Upstream knows about the issue and already fixed it [1] + [2]. Thorsten [1] https://github.com/benmcollins/libjwt/commit/f73bac57c5bece16ac24f1a70022aa34355fc1bf [2] https://github.com/benmcollins/libjwt/commit/a5d61ef4f1b383876e0a78534383f38159471fd6
Thanks. I think the real worl impact is pretty negligible, it's enough to land
a fix for the next release, but not for released suites.
Cheers,
Moritz
We believe that the bug you reported is fixed in the latest version of libjwt, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1063534@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Thorsten Alteholz <debian@alteholz.de> (supplier of updated libjwt package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sun, 18 Feb 2024 13:21:00 +0100 Source: libjwt Architecture: source Version: 1.17.0-1 Distribution: experimental Urgency: medium Maintainer: Debian IoT Maintainers <debian-iot-maintainers@lists.alioth.debian.org> Changed-By: Thorsten Alteholz <debian@alteholz.de> Closes: 1063534 Changes: libjwt (1.17.0-1) experimental; urgency=medium . * New upstream release. * Contains fix for CVE-2024-25189 (Closes: #1063534) * update symbols file Checksums-Sha1: 7b4963989b01c1c81744af8852e37f3155aeac0e 2357 libjwt_1.17.0-1.dsc 3f34d543213a9e36720cc097138cb9669f09e578 94260 libjwt_1.17.0.orig.tar.xz b3e8fb0d61228d3a34481f1447cf13ff4ac60df2 7024 libjwt_1.17.0-1.debian.tar.xz a0811f86dcdaac9fe9b5449c504e5039c11951d5 8739 libjwt_1.17.0-1_amd64.buildinfo Checksums-Sha256: 51ad7f431235f9265c3af74a578a934ad6be2f7f92e98fd530804a9b3280ee84 2357 libjwt_1.17.0-1.dsc ab1eaa34dbc4e8f3700810fedbb7c63de8b91aba967b002a1b4b78d99d406b7b 94260 libjwt_1.17.0.orig.tar.xz 1f50a8dd2ee21be22775063d9fa08ea42de491e293756396c31c9d94adce5c9a 7024 libjwt_1.17.0-1.debian.tar.xz 918ef938ecbe8fa81530d9c4d3b1a4a50d1c743a3f4b4053bbb1d770ebf3d711 8739 libjwt_1.17.0-1_amd64.buildinfo Files: 9001ab84f5bf9c8c148ebd9c2b1af4df 2357 devel optional libjwt_1.17.0-1.dsc cc73cfc393fe911634d42f33761864b9 94260 devel optional libjwt_1.17.0.orig.tar.xz 89f178bb1ba9aff8409937eda84ebd2a 7024 devel optional libjwt_1.17.0-1.debian.tar.xz 4b55bd9456b50ebd321b014ca9be4621 8739 devel optional libjwt_1.17.0-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmXR//xfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh bHRlaG9sei5kZQAKCRCW/KwNOHtYR5zeEACl9s/evcWPISzz+3I5lPC8BT187VWW LaWHc3Rxvq6hf2z/1UEKhwKO2SohHQQNFk0Uq0CFVJz2s3iC3iYW8wrKhhm8bUHa DQPLr1jjZynKhpcefWFe8480PDep0CntrVJoTN9Ut+hXpdY9wR3JspzvOwhuWLUr /FmgEK0ZhcAZMhMqEnjHQfG/muA1yzpiER0dJ76UcILZcPgQTtwxpcBpurJ3wYQH G9j34EVmTKvAo9JQZAZX8JVwWo6FVv5ikbm3u7UQL8UNYl3AEEtBfyjmmn6Yu6fr zzUHFKtzTkRbT2siyU5Va4d/FligDxeUKfNy7bJTOhP4+OBI4N5iwFZiHk5wpWkS 9ovIJveBOaYYnqUORQEriiNSAhtga/13ufGUEoeFq6IHK7ZAnFUTIs/bOkk6xMtt eA5TUFgxmB2NTihbAmBObJJvvZGQpwLCQlah6E6dde+n2vOOCWhoQFzFGBAPR6jq 1M8S7XY+uYCadLL1d7UQ+zhATiuPWNKkU4aPN9Oban0hkIaqx+17k4vsC1MdHzAF obCJmXCJeMtv6RvvKkQgIwGU7oQMdJrGsEd/4eEXIwAPXI4ucTDA+lo5UW7K0fMH YFzTUuFVNygB3r8ves9wuA1sOa3dVKqWTM3Y71beXe1cg6Y01k3Eepw3n0rF6w7D 5KBgmvrKCpPA/w== =ikxJ -----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
libjwt, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1063534@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thorsten Alteholz <debian@alteholz.de> (supplier of updated libjwt package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 20 Feb 2024 23:21:00 +0100
Source: libjwt
Architecture: source
Version: 1.17.0-2
Distribution: unstable
Urgency: medium
Maintainer: Debian IoT Maintainers <debian-iot-maintainers@lists.alioth.debian.org>
Changed-By: Thorsten Alteholz <debian@alteholz.de>
Closes: 1063534
Changes:
libjwt (1.17.0-2) unstable; urgency=medium
.
* finally upload to unstable
(fix for CVE-2024-25189 in unstable: Closes: #1063534)
(reverse dependencies did build successful, maintainers are aware)
Checksums-Sha1:
09507597155e49c69203aee54be94850acdd772a 2357 libjwt_1.17.0-2.dsc
3f34d543213a9e36720cc097138cb9669f09e578 94260 libjwt_1.17.0.orig.tar.xz
7bdfcb6f3ab00d0660904fa1acd0622df25fbe39 7128 libjwt_1.17.0-2.debian.tar.xz
13c0f945143026335b3fd48644d96971d4398ee6 8902 libjwt_1.17.0-2_amd64.buildinfo
Checksums-Sha256:
f53bd01f755d3ecd6060f0847af892767b659c4a0b9b64f1fe68f05fdc44a279 2357 libjwt_1.17.0-2.dsc
ab1eaa34dbc4e8f3700810fedbb7c63de8b91aba967b002a1b4b78d99d406b7b 94260 libjwt_1.17.0.orig.tar.xz
9922d7e12317e566295fa08aaf6e3ebca427414b4d4dd0d9933276f3681659eb 7128 libjwt_1.17.0-2.debian.tar.xz
c6d5369cadc908021a0ee883b6b387b87916903e4d9db0120f7f6f7dc74976ba 8902 libjwt_1.17.0-2_amd64.buildinfo
Files:
a3ae454e5c23d0dd4c0693c1e7a09e90 2357 devel optional libjwt_1.17.0-2.dsc
cc73cfc393fe911634d42f33761864b9 94260 devel optional libjwt_1.17.0.orig.tar.xz
bee733479c4898aa68172fabf7eb705a 7128 devel optional libjwt_1.17.0-2.debian.tar.xz
5a563adf6e47884695ef60b8c4cedf3b 8902 devel optional libjwt_1.17.0-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmXVJxBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYRzy/D/4oRY9jTrsanSwRbGjQKxUdxb0k+KST
mSCTbffSOQBfrvn+zkQt4cjKjhmZCQZo4GwfNh4ANjn7o1CbNJv8MnG1I5tgKTM8
u7owPuu5xLkSkLrF7PWx79Z1m+NqDW/COqo5unflXHTeCN52c91bg9IlmMrBxCSC
O/KNVRSlGovbSIqkvJ4bppj31m7joZs+/sx5T4aKPwa5N4cQ4iFJ9R9Fxeubog8N
832a/+zcaqN3c761ju5GsxN4QOMiHHh1X1u/bRuiwWiBpzhsOtTKEPD/lmrk71Gy
xSSST+07XDS/AE1weM0Np9SilLfju2nS1+DzvUuDkS8N5d16/KlKpfFl8271Dv3M
XfPT8rFmuqP2awrzyJVdeY7zBkOLXAosM56+xigXESWoZwT9CsqIJzJkZak5kiqJ
/pQcVgXr8i/ZgtqTIKCRTgthgvgcrX244xH1KKzUViKMITFPOUrUT24v3yGfHpbP
lJAZLTKX3Y1wrAH2DsFH+fmCHriRhgx7q9OQY3ZAJGHwpIdWXc75OG3WcoRnOte2
GrSP78z4ptD9PjLWbcRBicIMbQAxfWWFw1rgclmy5wXPmVqXdRIT1v4n+8pPe+/v
YPGbsKChtOInNsf8dHu24Q0dcUW1F4GVRelIm1gOhxKTMVOOoN+Kj1mdzmvXs20H
Qnf8oVm98GwmPA==
=QEXL
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
libjwt, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1063534@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thorsten Alteholz <debian@alteholz.de> (supplier of updated libjwt package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 19 Feb 2024 22:03:02 +0100
Source: libjwt
Architecture: source
Version: 1.10.2-1+deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: Debian IoT Maintainers <debian-iot-maintainers@lists.alioth.debian.org>
Changed-By: Thorsten Alteholz <debian@alteholz.de>
Closes: 1063534
Changes:
libjwt (1.10.2-1+deb12u1) bookworm; urgency=medium
.
* CVE-2024-25189 (Closes: #1063534)
fix a timing side channel via strcmp()
Checksums-Sha1:
21cea70ee7e9c8433f9ac38b271069d66537f66b 2383 libjwt_1.10.2-1+deb12u1.dsc
98dbc31978c5b716865cefea570f125bd2a1e9f7 80584 libjwt_1.10.2.orig.tar.xz
10ffa3f60c0ac8fc04b44dbb5c0820167c312e58 8324 libjwt_1.10.2-1+deb12u1.debian.tar.xz
b544a69ef3e1688f6e0290d9135268a8dc64517c 8767 libjwt_1.10.2-1+deb12u1_amd64.buildinfo
Checksums-Sha256:
8ba39d57a09d867bfb7138e5f8527dbc496fbf5c820f36b4150ea96d1c512b7e 2383 libjwt_1.10.2-1+deb12u1.dsc
648802b0c1fc5ef818f62cb8a4f2c570e7130130eb01ba056f1d6ae4c0f9f981 80584 libjwt_1.10.2.orig.tar.xz
95e8f81ace98b6bf9521630258ed6efe47ffe0ce882b0c8ecd13197fdc55c790 8324 libjwt_1.10.2-1+deb12u1.debian.tar.xz
e4204384a4108ef33da102bf96da754f14709b6ce1af79866c14c8362ac23a03 8767 libjwt_1.10.2-1+deb12u1_amd64.buildinfo
Files:
d1685e924b200c6bad9deccb5621f2cc 2383 devel optional libjwt_1.10.2-1+deb12u1.dsc
79ec14c70b2f3754cd2be3c167d7a8b1 80584 devel optional libjwt_1.10.2.orig.tar.xz
b38ef561b93863b49a475d911a4516d8 8324 devel optional libjwt_1.10.2-1+deb12u1.debian.tar.xz
20fcbdb9eb160717e27fdbc282736603 8767 devel optional libjwt_1.10.2-1+deb12u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKnBAEBCgCRFiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmXjvRFfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcTHGRlYmlhbkBh
bHRlaG9sei5kZQAKCRCW/KwNOHtYR9XmD/40CaUN7DYRC3rHoxfihewaej9G7iFV
P+jesN67YD4haBaY1UDtu1qy4Ws9VmUCY6gyH/u2gcp9paIgZ7ZwUZ5bHvsgDF3o
Mal2qn4RhQAZRJnho9olrFnHznLJVhYguuQ0x7SQscty0MFNIWF8IOQcTj78sOk6
mwp3FdHMOgU8pD7cRwdaFIkQKfWBjvIpi4PC12BsdAOBuG5LHFRQw+ZOSqH71qn2
jyn6Qm9eCaQx93mQdQEvalWcYk5u06TVcQ/r6cGKCnt7cN/0vcv3FAp+cmypOFEK
zam4IlITfAFbZikhqUqRVtAi9H9es5w+YdAvaj7nTi4odasnxrlYXZUiLanNomUs
JPIZhtxk3M/JW7BK6VYuRXN+yTbLtm3Rg9drk/tv0GkiHvI58M8Xw2FXoWyv6kPZ
sFfUdYP7N+9qxgwL8A2/i6E+gJIQlxkMcFP0Fsi8IDFx/T5D4MUaaXwt72j3ORXg
UUCsD8OOUd2PMKJUBZ9TCuxfLsNJskKjt1SqW+1ZWup4KIVd7+kvHFK3t0o0lxmu
5jZp5j+ffkStt1zLf0P1FeIUYHv62NT20G+TzyBaYOw5DyGonm8Vrb9mQYJU2Hih
esDvTeZMLPl7jo7nDezQssED3TV/rCdvK82jXy42zwGQ5xr20W00GMc0Ql9q7WJE
k8Xis34/58vfYQ==
=KB01
-----END PGP SIGNATURE-----