[ALAS-2023-1825] Amazon Linux AMI 2014.03 - ALAS-2023-1825: important priority package update for amazon-ssm-agent

Severity Important
Affected Packages 2
CVEs 4

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2022-41723:
http2/hpack: avoid quadratic complexity in hpack decoding

CVE-2022-27664:
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.

CVE-2022-27191:
A broken cryptographic algorithm flaw was found in golang.org/x/crypto/ssh. This issue causes a client to fail authentification with RSA keys to servers that reject signature algorithms based on SHA-2, enabling an attacker to crash the server, resulting in a loss of availability.

CVE-2021-43565:
The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an SSH server.

ID
ALAS-2023-1825
Severity
important
URL
https://alas.aws.amazon.com/ALAS-2023-1825.html
Published
2023-08-30T18:41:00
(12 months ago)
Modified
2023-09-09T00:34:00
(12 months ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/amazon-ssm-agent?arch=x86_64&distro=amazonlinux-1 amazonlinux amazon-ssm-agent < 3.2.1377.0-1.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/amazon-ssm-agent-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux amazon-ssm-agent-debuginfo < 3.2.1377.0-1.amzn1 amazonlinux-1 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...