Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2022:4567-1

Опубликовано: 19 дек. 2022
Источник: suse-cvrf

Описание

Recommended update for python-crcmod, python-cryptography, python-cryptography-vectors

This update for python-crcmod, python-cryptography, python-cryptography-vectors contains the following fixes:

python-cryptography:

  • Update in SLE-15 (bsc#1177083, jsc#PM-2730, jsc#SLE-18312)
  • Refresh patches for new version
  • Using the Fernet class to symmetrically encrypt multi gigabyte values. (bsc#1182066, CVE-2020-36242) could result in an integer overflow and buffer overflow.
  • update to 2.9.2
    • 2.9.2 - 2020-04-22
      • Updated the macOS wheel to fix an issue where it would not run on macOS versions older than 10.15.
    • 2.9.1 - 2020-04-21
      • Updated Windows, macOS, and manylinux wheels to be compiled with OpenSSL 1.1.1g.
    • 2.9 - 2020-04-02
      • BACKWARDS INCOMPATIBLE: Support for Python 3.4 has been removed due to low usage and maintenance burden.
      • BACKWARDS INCOMPATIBLE: Support for OpenSSL 1.0.1 has been removed. Users on older version of OpenSSL will need to upgrade.
      • BACKWARDS INCOMPATIBLE: Support for LibreSSL 2.6.x has been removed.
      • Removed support for calling public_bytes() with no arguments, as per our deprecation policy. You must now pass encoding and format.
      • BACKWARDS INCOMPATIBLE: Reversed the order in which rfc4514_string() returns the RDNs as required by RFC 4514.
      • Updated Windows, macOS, and manylinux wheels to be compiled with OpenSSL 1.1.1f.
      • Added support for parsing single_extensions in an OCSP response.
      • NameAttribute values can now be empty strings.

Changes in python-cryptography-vectors:

  • Update in SLE-15 (bsc#1177083, jsc#PM-2730, jsc#SLE-18312)

  • update to 2.9.2:

    • updated vectors for the cryptography 2.9.2 testing

Список пакетов

Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Enterprise Storage 6
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Linux Enterprise Module for Public Cloud 15 SP1
python2-cryptography-vectors-2.9.2-150000.3.7.1
SUSE Linux Enterprise Server 15 SP1-BCL
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Linux Enterprise Server 15 SP1-LTSS
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Linux Enterprise Server for SAP Applications 15 SP1
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2

Описание

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.


Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:python3-cffi-1.15.0-150000.4.11.2
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:python3-cryptography-2.9.2-150100.7.8.2
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:python3-cffi-1.15.0-150000.4.11.2
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:python3-cryptography-2.9.2-150100.7.8.2

Ссылки