Search CVE reports
1 – 3 of 3 results
(OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
1 affected package
cjose
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cjose | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
(OpenIDC/cjose is a C library implementing the Javascript Object Signin ...)
1 affected package
cjose
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cjose | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
Some fixes available 4 of 11
OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says...
1 affected package
cjose
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| cjose | Needs evaluation | Needs evaluation | Fixed | Fixed | Fixed |