USN-6059-1

Source
https://ubuntu.com/security/notices/USN-6059-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6059-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6059-1
Upstream
Related
Published
2023-05-08T08:40:04Z
Modified
2026-02-10T04:43:07Z
Summary
erlang vulnerability
Details

It was discovered that Erlang did not properly implement TLS client certificate validation during the TLS handshake. A remote attacker could use this issue to bypass client authentication.

References

Affected packages

Ubuntu:20.04:LTS / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:22.2.7+dfsg-1ubuntu0.2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:22.2.7+dfsg-1ubuntu0.2

Affected versions

1:22.*
1:22.0.7+dfsg-1build1
1:22.2+dfsg-1
1:22.2.1+dfsg-1
1:22.2.2+dfsg-1
1:22.2.3+dfsg-1
1:22.2.3+dfsg-2
1:22.2.4+dfsg-1
1:22.2.7+dfsg-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-asn1"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-base"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-base-hipe"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-common-test"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-crypto"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-debugger"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-dev"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-dialyzer"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-diameter"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-edoc"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-eldap"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-erl-docgen"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-et"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-eunit"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-examples"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-ftp"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-inets"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-jinterface"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-manpages"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-megaco"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-mnesia"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-mode"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-nox"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-observer"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-odbc"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-os-mon"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-parsetools"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-public-key"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-reltool"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-runtime-tools"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-snmp"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-src"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-ssh"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-ssl"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-syntax-tools"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-tftp"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-tools"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-wx"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-x11"
        },
        {
            "binary_version": "1:22.2.7+dfsg-1ubuntu0.2",
            "binary_name": "erlang-xmerl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6059-1.json"
cves_map
{
    "ecosystem": "Ubuntu:20.04:LTS",
    "cves": [
        {
            "id": "CVE-2022-37026",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}

Ubuntu:22.04:LTS / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:24.2.1+dfsg-1ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:24.2.1+dfsg-1ubuntu0.1

Affected versions

1:23.*
1:23.2.6+dfsg-1build1
1:24.*
1:24.1.1+dfsg-1
1:24.1.4+dfsg-1
1:24.1.5+dfsg-1
1:24.1.5+dfsg-1ubuntu1
1:24.2+dfsg-1
1:24.2.1+dfsg-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-asn1"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-base"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-common-test"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-crypto"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-debugger"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-dev"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-dialyzer"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-diameter"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-edoc"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-eldap"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-erl-docgen"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-et"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-eunit"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-examples"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-ftp"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-inets"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-jinterface"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-manpages"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-megaco"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-mnesia"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-mode"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-nox"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-observer"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-odbc"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-os-mon"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-parsetools"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-public-key"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-reltool"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-runtime-tools"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-snmp"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-src"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-ssh"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-ssl"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-syntax-tools"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-tftp"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-tools"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-wx"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-x11"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.1",
            "binary_name": "erlang-xmerl"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6059-1.json"
cves_map
{
    "ecosystem": "Ubuntu:22.04:LTS",
    "cves": [
        {
            "id": "CVE-2022-37026",
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ]
        }
    ]
}