File _patchinfo of Package patchinfo.30414
<patchinfo incident="30414"> <issue tracker="cve" id="2023-29409"/> <issue tracker="bnc" id="1213880">VUL-0: CVE-2023-29409: go1.19,go1.20: crypto/tls: restrict RSA keys in certificates to <= 8192 bits</issue> <packager>deneb_alpha</packager> <rating>important</rating> <category>security</category> <summary>Security update for Golang Prometheus</summary> <description>This update for Golang Prometheus fixes the following issues: golang-github-prometheus-alertmanager: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. golang-github-prometheus-node_exporter: - CVE-2023-29409: Restrict RSA keys in certificates to less than or equal to 8192 bits to avoid DoSing client/server while validating signatures for extremely large RSA keys. (bsc#1213880) There are no direct source changes. The CVE is fixed rebuilding the sources with the patched Go version. </description> </patchinfo>




