REDHAT-BUG-2444025: High severity AWS AWS-LC vulnerability
Improper signature validation in PKCS7verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.
Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AWS-LCto a version that resolves this vulnerability.Fixed in 1.69.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2444025?
The severity of REDHAT-BUG-2444025 is classified as high, with a score of 7.
How do I fix REDHAT-BUG-2444025?
To fix REDHAT-BUG-2444025, users should upgrade to AWS-LC version 1.69 or later.
Who is affected by REDHAT-BUG-2444025?
REDHAT-BUG-2444025 affects applications using AWS-LC that process PKCS7 objects with Authenticated Attributes.
What vulnerability does REDHAT-BUG-2444025 describe?
REDHAT-BUG-2444025 describes an improper signature validation issue in the PKCS7_verify() function of AWS-LC.
Is user action required for AWS service customers regarding REDHAT-BUG-2444025?
Customers of AWS services do not need to take action regarding REDHAT-BUG-2444025.