Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:4044-1

Опубликовано: 17 нояб. 2022
Источник: suse-cvrf

Описание

Security update for python-cryptography, python-cryptography-vectors

This update for python-cryptography, python-cryptography-vectors fixes the following issues:

  • Update in SLE-15 (bsc#1177083, jsc#PM-2730, jsc#SLE-18312)

  • Refresh patches for new version

  • Update in SLE-15 (bsc#1176785, jsc#ECO-3105, jsc#PM-2352)

  • update to 2.9.2

    • 2.9.2 - 2020-04-22
      • Updated the macOS wheel to fix an issue where it would not run on macOS versions older than 10.15.
    • 2.9.1 - 2020-04-21
      • Updated Windows, macOS, and manylinux wheels to be compiled with OpenSSL 1.1.1g.
    • 2.9 - 2020-04-02
      • BACKWARDS INCOMPATIBLE: Support for Python 3.4 has been removed due to low usage and maintenance burden.
      • BACKWARDS INCOMPATIBLE: Support for OpenSSL 1.0.1 has been removed. Users on older version of OpenSSL will need to upgrade.
      • BACKWARDS INCOMPATIBLE: Support for LibreSSL 2.6.x has been removed.
      • Removed support for calling public_bytes() with no arguments, as per our deprecation policy. You must now pass encoding and format.
      • BACKWARDS INCOMPATIBLE: Reversed the order in which rfc4514_string() returns the RDNs as required by RFC 4514.
      • Updated Windows, macOS, and manylinux wheels to be compiled with OpenSSL 1.1.1f.
      • Added support for parsing single_extensions in an OCSP response.
      • NameAttribute values can now be empty strings.
  • Add openSSL_111d.patch to make this version of the package compatible with OpenSSL 1.1.1d, thus fixing bsc#1149792.

  • bsc#1101820 CVE-2018-10903 GCM tag forgery via truncated tag in finalize_with_tag API

  • Update in SLE-15 (bsc#1177083, jsc#PM-2730, jsc#SLE-18312)

  • Include in SLE-15 (bsc#1176785, jsc#ECO-3105, jsc#PM-2352)

  • update to 2.9.2:

    • updated vectors for the cryptography 2.9.2 testing

Список пакетов

Container ses/7.1/cephcsi/cephcsi:latest
python3-cryptography-2.9.2-150200.13.1
Container ses/7.1/rook/ceph:latest
python3-cryptography-2.9.2-150200.13.1
Container trento/trento-runner:latest
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-HPC-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-SAP-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-SAP-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-SAP-BYOS-EC2-HVM
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-SAP-BYOS-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-SAP-EC2-HVM
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-SAP-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-BYOS-EC2-HVM
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-BYOS-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-CHOST-BYOS-Aliyun
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-CHOST-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-CHOST-BYOS-EC2
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-CHOST-BYOS-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-CHOST-BYOS-SAP-CCloud
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-HPC-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-HPC-BYOS-EC2-HVM
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-HPC-BYOS-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-EC2-HVM
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Micro-5-1-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Micro-5-1-BYOS-EC2-HVM
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Micro-5-1-BYOS-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Micro-5-2-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Micro-5-2-BYOS-EC2-HVM
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-Micro-5-2-BYOS-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-SAP-BYOS-Azure
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-SAP-BYOS-EC2-HVM
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-SAP-BYOS-GCE
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-SAPCAL-Azure
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-SAPCAL-EC2-HVM
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP3-SAPCAL-GCE
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
SUSE Enterprise Storage 7
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise Micro 5.1
python3-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise Micro 5.2
python3-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
python3-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise Module for Python 2 15 SP3
python2-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise Server 15 SP2-BCL
python3-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise Server 15 SP2-LTSS
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
SUSE Manager Proxy 4.1
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
SUSE Manager Retail Branch Server 4.1
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
SUSE Manager Server 4.1
python2-cryptography-2.9.2-150200.13.1
python3-cryptography-2.9.2-150200.13.1
openSUSE Leap 15.3
python2-cryptography-2.9.2-150200.13.1
python2-cryptography-vectors-2.9.2-150200.3.3.1
python3-cryptography-2.9.2-150200.13.1
python3-cryptography-vectors-2.9.2-150200.3.3.1
openSUSE Leap Micro 5.2
python3-cryptography-2.9.2-150200.13.1

Описание

A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.


Затронутые продукты
Container ses/7.1/cephcsi/cephcsi:latest:python3-cryptography-2.9.2-150200.13.1
Container ses/7.1/rook/ceph:latest:python3-cryptography-2.9.2-150200.13.1
Container trento/trento-runner:latest:python3-cryptography-2.9.2-150200.13.1
Image SLES15-SP2-BYOS-Azure:python3-cryptography-2.9.2-150200.13.1

Ссылки
Уязвимость SUSE-SU-2022:4044-1