Описание
Recommended update for aws-cli, python-boto3, python-botocore, python-s3transfer
This update for aws-cli, python-boto3, python-botocore, python-s3transfer fixes the following issues:
aws-cli:
- Update to version 1.16.61. (bsc#1088310)
- For detailed changes see https://github.com/aws/aws-cli/blob/1.16.1/CHANGELOG.rst
- Update to version 1.16.1 (bsc#1105988, bsc#1092493)
- CVE-2018-15869: An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, might have unintentionally loaded an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.
- Disable vendored versions of requests and six from botocore and use requests and six from the RPM packages.
python-botocore:
- Update to version 1.10.40
- For detailed changes, please refer to the changelog.
- Remove the broken attempt to avoid using the bundeled requests module provided by the source (bsc#1088310)
python-boto3:
- Version update to 1.9.57 (bsc#1118021, bsc#1118027)
- For detailed changes, please refer to the changelog.
python-s3transfer:
- Update to version 0.1.13
- Make sure to really not use any bundles.
- enhancement:max_bandwidth: Add ability to set maximum bandwidth consumption for streaming of S3 uploads and downloads.
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15
python3-boto3-1.9.57-3.5.1
python3-botocore-1.12.57-3.5.1
python3-s3transfer-0.1.13-3.3.6
SUSE Linux Enterprise Module for Package Hub 15
python2-boto3-1.9.57-3.5.1
python2-botocore-1.12.57-3.5.1
python2-s3transfer-0.1.13-3.3.6
SUSE Linux Enterprise Module for Public Cloud 15
aws-cli-1.16.61-4.7.1
Ссылки
- Link for SUSE-RU-2018:4074-1
- E-Mail link for SUSE-RU-2018:4074-1
- SUSE Security Ratings
- SUSE Bug 1088310
- SUSE Bug 1092493
- SUSE Bug 1098125
- SUSE Bug 1105988
- SUSE Bug 1118021
- SUSE Bug 1118027
- SUSE CVE CVE-2018-15869 page
Описание
An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, may unintentionally load an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15:python3-boto3-1.9.57-3.5.1
SUSE Linux Enterprise Module for Basesystem 15:python3-botocore-1.12.57-3.5.1
SUSE Linux Enterprise Module for Basesystem 15:python3-s3transfer-0.1.13-3.3.6
SUSE Linux Enterprise Module for Package Hub 15:python2-boto3-1.9.57-3.5.1
Ссылки
- CVE-2018-15869
- SUSE Bug 1105988