Total vulnerabilities in the database
In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)
Software | From | Fixed in |
---|---|---|
rhonabwy_project / rhonabwy | - | 1.1.3.x |
debian / debian_linux | 11.0 | 11.0.x |
debian / debian_linux | 12.0 | 12.0.x |