INFBA-2024:5691: ca-certificates security update
Information about definition
Identificator: INFBA-2024:5691
Type: bugfix
Release date: 2024-12-27 09:17:59 UTC
Information about package
The ca-certificates package contains a set of Certificate Authority (CA) certificates chosen by the Mozilla Foundation for use with the Internet Public Key Infrastructure (PKI).
Vulnerabilities description
- CVE-2023-37920
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. Bug Fixes and Enhancements: * Annual 2024 ca-certificates update version 2.69 from NSS 3.101.1 for Firefox 128 [rhel-9.4.z]. * Provide ca-certificates in directory format to resolve Application performance regression in OpenSSL [rhel-9.4.z]. * calling update-ca-trust on RHEL-9 should be supported with just about any argument [rhel-9.4.z].
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2023-37920
|
no information | 9.1 | no information |
Updated packages