Описание
Recommended update for python-crcmod, python-cryptography, python-cryptography-vectors
This update for python-crcmod, python-cryptography, python-cryptography-vectors contains the following fixes:
python-cryptography:
- Update in SLE-15 (bsc#1177083, jsc#PM-2730, jsc#SLE-18312)
- Refresh patches for new version
- Using the Fernet class to symmetrically encrypt multi gigabyte values. (bsc#1182066, CVE-2020-36242) could result in an integer overflow and buffer overflow.
- update to 2.9.2
- 2.9.2 - 2020-04-22
- Updated the macOS wheel to fix an issue where it would not run on macOS versions older than 10.15.
- 2.9.1 - 2020-04-21
- Updated Windows, macOS, and manylinux wheels to be compiled with OpenSSL 1.1.1g.
- 2.9 - 2020-04-02
- BACKWARDS INCOMPATIBLE: Support for Python 3.4 has been removed due to low usage and maintenance burden.
- BACKWARDS INCOMPATIBLE: Support for OpenSSL 1.0.1 has been removed. Users on older version of OpenSSL will need to upgrade.
- BACKWARDS INCOMPATIBLE: Support for LibreSSL 2.6.x has been removed.
- Removed support for calling public_bytes() with no arguments, as per our deprecation policy. You must now pass encoding and format.
- BACKWARDS INCOMPATIBLE: Reversed the order in which rfc4514_string() returns the RDNs as required by RFC 4514.
- Updated Windows, macOS, and manylinux wheels to be compiled with OpenSSL 1.1.1f.
- Added support for parsing single_extensions in an OCSP response.
- NameAttribute values can now be empty strings.
- 2.9.2 - 2020-04-22
Changes in python-cryptography-vectors:
-
Update in SLE-15 (bsc#1177083, jsc#PM-2730, jsc#SLE-18312)
-
update to 2.9.2:
- updated vectors for the cryptography 2.9.2 testing
Список пакетов
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Enterprise Storage 6
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Linux Enterprise Module for Public Cloud 15 SP1
python2-cryptography-vectors-2.9.2-150000.3.7.1
SUSE Linux Enterprise Server 15 SP1-BCL
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Linux Enterprise Server 15 SP1-LTSS
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
SUSE Linux Enterprise Server for SAP Applications 15 SP1
python2-bcrypt-3.1.4-150100.6.2.1
python2-cffi-1.15.0-150000.4.11.2
python2-cryptography-2.9.2-150100.7.8.2
python3-bcrypt-3.1.4-150100.6.2.1
python3-cffi-1.15.0-150000.4.11.2
python3-cryptography-2.9.2-150100.7.8.2
Ссылки
- Link for SUSE-RU-2022:4567-1
- E-Mail link for SUSE-RU-2022:4567-1
- SUSE Security Ratings
- SUSE Bug 1177083
- SUSE CVE CVE-2020-36242 page
Описание
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
Затронутые продукты
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:python3-cffi-1.15.0-150000.4.11.2
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:python3-cryptography-2.9.2-150100.7.8.2
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:python3-cffi-1.15.0-150000.4.11.2
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production:python3-cryptography-2.9.2-150100.7.8.2
Ссылки
- CVE-2020-36242
- SUSE Bug 1182066