Bug#1067457: jose: CVE-2023-50967

2024-03-21 Thread Christoph Biedl
Control: forwarded 1067457 https://github.com/latchset/jose/issues/151 signature.asc Description: PGP signature

Bug#1067457: jose: CVE-2023-50967

2024-03-21 Thread Moritz Mühlenhoff
Source: jose X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for jose. CVE-2023-50967[0]: | latchset jose through version 11 allows attackers to cause a denial | of service (CPU consumption) via a large p2c (aka PBES2