Issue with configuring session ticket names in s2n-tls
MediumPublished Sep 27, 2022
A bug in s2n-tls results in the inadvertent copying of memory when configuring session ticket names. As a result, s2n-tls servers which set a session ticket name with length less than 16 bytes can potentially disclose some random memory. Servers which set a 16-byte name are unaffected. No AWS service was affected by this issue and customers of AWS services do not need to take action. Server applications using s2n-tls with session resumption should update to the most recent version. All versions of s2n-tls from commit cc339f5 to c947a221e1caadf12a262a6bf548f5f082e096be are affected by this issue. s2n-tls users should fetch s2n-tls commit e6e8b6ad2db5c21a95df05e2367654b3d4c08846.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| s2n-tls Product | < v1.3.23 | v1.3.23 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 142023 | Issue with parsing Certificate Common Name (CN) in s2n-tls | Low | v1.3.35 |
| Dec 102022 | Privilege Escalation Vector in CloudWatch Agent for Windows | High7.1 | 1.247355 |
| Sep 272022 | Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake | Low | <v1.3.23 |
| Aug 92022 | Partial Path Traversal in aws-cpp-sdk-transfer | Medium | v1.9.318 |
| Jul 152022 | Partial Path Traversal in com.amazonaws:aws-java-sdk-s3 | High7.9 | 1.12.261 |
| May 162022 | Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8 | Critical | 20.11.9 |