Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:2783-1

Опубликовано: 04 июл. 2023
Источник: suse-cvrf

Описание

Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets

This update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets fixes the following issues:

grpc:

  • Update in SLE-15 (bsc#1197726, bsc#1144068)

protobuf:

  • Fix a potential DoS issue in protobuf-cpp and protobuf-python, CVE-2022-1941, bsc#1203681
  • Fix a potential DoS issue when parsing with binary data in protobuf-java, CVE-2022-3171, bsc#1204256
  • Fix potential Denial of Service in protobuf-java in the parsing procedure for binary data, CVE-2021-22569, bsc#1194530
  • Add missing dependency of python subpackages on python-six (bsc#1177127)
  • Updated to version 3.9.2 (bsc#1162343)
    • Remove OSReadLittle* due to alignment requirements.
    • Don't use unions and instead use memcpy for the type swaps.
  • Disable LTO (bsc#1133277)

python-aiocontextvars:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)

python-avro:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)

python-cryptography:

  • update to 3.3.2 (bsc#1182066, CVE-2020-36242, bsc#1198331)
    • SECURITY ISSUE: Fixed a bug where certain sequences of update() calls when symmetrically encrypting very large payloads (>2GB) could result in an integer overflow, leading to buffer overflows. CVE-2020-36242

python-cryptography-vectors:

  • update to 3.2 (bsc#1178168, CVE-2020-25659):
    • CVE-2020-25659: Attempted to make RSA PKCS#1v1.5 decryption more constant time, to protect against Bleichenbacher vulnerabilities. Due to limitations imposed by our API, we cannot completely mitigate this vulnerability.
    • Support for OpenSSL 1.0.2 has been removed.
    • Added basic support for PKCS7 signing (including SMIME) via PKCS7SignatureBuilder.
  • update to 3.3.2 (bsc#1198331)

python-Deprecated:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • update to 1.2.13:

python-google-api-core:

  • Update to 1.14.2

python-googleapis-common-protos:

  • Update to 1.6.0

python-grpcio-gcp:

  • Initial spec for v0.2.2

python-humanfriendly:

  • Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Update to 10.0

python-jsondiff:

  • Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Update to version 1.3.0

python-knack:

  • Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Update to version 0.9.0

python-opencensus:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Disable Python2 build
  • Update to 0.8.0

python-opencensus-context:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)

python-opencensus-ext-threading:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Initial build version 0.1.2

python-opentelemetry-api:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Version update to 1.5.0

python-psutil:

  • Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • update to 5.9.1
  • remove the dependency on net-tools, since it conflicts with busybox-hostnmame which is default on MicroOS. (bsc#1184753)
  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)

python-PyGithub:

  • Update to 1.43.5:

python-pytest-asyncio:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Initial release of python-pytest-asyncio 0.8.0

python-requests:

  • Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)

python-websocket-client:

  • Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • Update to version 1.3.2

python-websockets:

  • Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
  • update to 9.1:

Список пакетов

Container ses/7.1/cephcsi/cephcsi:latest
python3-websocket-client-1.3.2-150100.6.7.3
Container ses/7.1/rook/ceph:latest
python3-websocket-client-1.3.2-150100.6.7.3
Container suse/sle15:15.1
libprotobuf-lite20-3.9.2-150100.8.3.3
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
libprotobuf-lite20-3.9.2-150100.8.3.3
python3-cryptography-3.3.2-150100.7.15.3
python3-humanfriendly-10.0-150100.6.3.3
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
libprotobuf-lite20-3.9.2-150100.8.3.3
python3-cryptography-3.3.2-150100.7.15.3
python3-humanfriendly-10.0-150100.6.3.3
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
Image SLES15-SP2-BYOS-Azure
azure-cli-core-2.17.1-150100.6.18.1
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
Image SLES15-SP2-HPC-BYOS-Azure
azure-cli-core-2.17.1-150100.6.18.1
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
Image SLES15-SP2-SAP-Azure
azure-cli-core-2.17.1-150100.6.18.1
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
Image SLES15-SP2-SAP-BYOS-Azure
azure-cli-core-2.17.1-150100.6.18.1
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
Image SLES15-SP2-SAP-BYOS-EC2-HVM
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
Image SLES15-SP2-SAP-BYOS-GCE
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
Image SLES15-SP2-SAP-EC2-HVM
python3-requests-2.25.1-150100.6.13.3
Image SLES15-SP2-SAP-GCE
python3-requests-2.25.1-150100.6.13.3
Image SLES15-SP3-BYOS-Azure
python3-Automat-0.6.0-150000.3.4.1
python3-Deprecated-1.2.13-150100.3.3.3
python3-PyGithub-1.43.5-150100.3.3.3
python3-aiocontextvars-0.2.2-150100.3.3.3
python3-avro-1.11.0-150100.3.3.3
python3-constantly-15.1.0-150000.3.4.1
python3-humanfriendly-10.0-150100.6.3.3
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-opencensus-0.8.0-150100.3.3.3
python3-opencensus-context-0.1.2-150100.3.3.3
python3-opencensus-ext-threading-0.1.2-150100.3.3.3
python3-opentelemetry-api-1.5.0-150100.3.3.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
Image SLES15-SP3-HPC-BYOS-Azure
python3-Automat-0.6.0-150000.3.4.1
python3-Deprecated-1.2.13-150100.3.3.3
python3-PyGithub-1.43.5-150100.3.3.3
python3-aiocontextvars-0.2.2-150100.3.3.3
python3-avro-1.11.0-150100.3.3.3
python3-constantly-15.1.0-150000.3.4.1
python3-humanfriendly-10.0-150100.6.3.3
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-opencensus-0.8.0-150100.3.3.3
python3-opencensus-context-0.1.2-150100.3.3.3
python3-opencensus-ext-threading-0.1.2-150100.3.3.3
python3-opentelemetry-api-1.5.0-150100.3.3.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
Image SLES15-SP3-Manager-4-2-Proxy-BYOS-Azure
azure-cli-core-2.17.1-150100.6.18.1
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-websocket-client-1.3.2-150100.6.7.3
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
azure-cli-core-2.17.1-150100.6.18.1
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-websocket-client-1.3.2-150100.6.7.3
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP3-SAP-BYOS-Azure
python3-Automat-0.6.0-150000.3.4.1
python3-Deprecated-1.2.13-150100.3.3.3
python3-PyGithub-1.43.5-150100.3.3.3
python3-aiocontextvars-0.2.2-150100.3.3.3
python3-avro-1.11.0-150100.3.3.3
python3-constantly-15.1.0-150000.3.4.1
python3-humanfriendly-10.0-150100.6.3.3
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-opencensus-0.8.0-150100.3.3.3
python3-opencensus-context-0.1.2-150100.3.3.3
python3-opencensus-ext-threading-0.1.2-150100.3.3.3
python3-opentelemetry-api-1.5.0-150100.3.3.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
Image SLES15-SP3-SAPCAL-Azure
python3-Automat-0.6.0-150000.3.4.1
python3-Deprecated-1.2.13-150100.3.3.3
python3-PyGithub-1.43.5-150100.3.3.3
python3-aiocontextvars-0.2.2-150100.3.3.3
python3-avro-1.11.0-150100.3.3.3
python3-constantly-15.1.0-150000.3.4.1
python3-humanfriendly-10.0-150100.6.3.3
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-opencensus-0.8.0-150100.3.3.3
python3-opencensus-context-0.1.2-150100.3.3.3
python3-opencensus-ext-threading-0.1.2-150100.3.3.3
python3-opentelemetry-api-1.5.0-150100.3.3.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
Image SLES15-SP4-SAP-Azure-LI-BYOS
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP4-SAP-Azure-VLI-BYOS
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP5-SAP-Azure-LI-BYOS
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP5-SAP-Azure-VLI-BYOS
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP6-SAP-Azure-LI-BYOS
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP6-SAP-Azure-VLI-BYOS
python3-humanfriendly-10.0-150100.6.3.3
Image SLES15-SP6-SAP-Azure-VLI-BYOS-Production
python3-humanfriendly-10.0-150100.6.3.3
SUSE Enterprise Storage 7
python2-psutil-5.9.1-150100.6.6.3
python2-requests-2.25.1-150100.6.13.3
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Enterprise Storage 7.1
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
libprotobuf-lite20-3.9.2-150100.8.3.3
python2-cryptography-3.3.2-150100.7.15.3
python2-psutil-5.9.1-150100.6.6.3
python2-requests-2.25.1-150100.6.13.3
python3-cryptography-3.3.2-150100.7.15.3
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
python2-psutil-5.9.1-150100.6.6.3
python2-requests-2.25.1-150100.6.13.3
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Installer Updates 15 SP1
libprotobuf-lite20-3.9.2-150100.8.3.3
SUSE Linux Enterprise Module for Basesystem 15 SP4
python3-websocket-client-1.3.2-150100.6.7.3
SUSE Linux Enterprise Module for Basesystem 15 SP5
python3-websocket-client-1.3.2-150100.6.7.3
SUSE Linux Enterprise Module for Package Hub 15 SP5
python2-humanfriendly-10.0-150100.6.3.3
SUSE Linux Enterprise Module for Public Cloud 15 SP1
azure-cli-core-2.17.1-150100.6.18.1
grpc-devel-1.25.0-150100.3.3.3
grpc-source-1.25.0-150100.3.3.3
libgrpc++1-1.25.0-150100.3.3.3
libgrpc8-1.25.0-150100.3.3.3
libprotobuf-lite20-3.9.2-150100.8.3.3
libprotobuf-lite20-32bit-3.9.2-150100.8.3.3
libprotobuf20-3.9.2-150100.8.3.3
libprotobuf20-32bit-3.9.2-150100.8.3.3
libprotoc20-3.9.2-150100.8.3.3
libprotoc20-32bit-3.9.2-150100.8.3.3
protobuf-devel-3.9.2-150100.8.3.3
protobuf-java-3.9.2-150100.8.3.3
protobuf-source-3.9.2-150100.8.3.3
python2-cryptography-3.3.2-150100.7.15.3
python2-cryptography-vectors-3.3.2-150100.3.11.3
python2-googleapis-common-protos-1.6.0-150100.3.3.3
python2-grpcio-1.25.0-150100.3.3.3
python2-grpcio-gcp-0.2.2-150100.3.3.3
python2-jsondiff-1.3.0-150100.3.6.3
python2-protobuf-3.9.2-150100.8.3.3
python2-psutil-5.9.1-150100.6.6.3
python2-requests-2.25.1-150100.6.13.3
python3-Deprecated-1.2.13-150100.3.3.3
python3-PyGithub-1.43.5-150100.3.3.3
python3-Twisted-17.9.0-150000.3.8.1
python3-aiocontextvars-0.2.2-150100.3.3.3
python3-avro-1.11.0-150100.3.3.3
python3-cryptography-3.3.2-150100.7.15.3
python3-cryptography-vectors-3.3.2-150100.3.11.3
python3-google-api-core-1.14.2-150100.3.3.3
python3-googleapis-common-protos-1.6.0-150100.3.3.3
python3-grpcio-1.25.0-150100.3.3.3
python3-grpcio-gcp-0.2.2-150100.3.3.3
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-opencensus-0.8.0-150100.3.3.3
python3-opencensus-context-0.1.2-150100.3.3.3
python3-opencensus-ext-threading-0.1.2-150100.3.3.3
python3-opentelemetry-api-1.5.0-150100.3.3.3
python3-protobuf-3.9.2-150100.8.3.3
python3-psutil-5.9.1-150100.6.6.3
python3-pytest-3.10.1-150000.7.5.1
python3-pytest-asyncio-0.8.0-150100.3.3.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-websockets-9.1-150100.3.3.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Module for Public Cloud 15 SP2
azure-cli-core-2.17.1-150100.6.18.1
python3-Deprecated-1.2.13-150100.3.3.3
python3-PyGithub-1.43.5-150100.3.3.3
python3-aiocontextvars-0.2.2-150100.3.3.3
python3-avro-1.11.0-150100.3.3.3
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-opencensus-0.8.0-150100.3.3.3
python3-opencensus-context-0.1.2-150100.3.3.3
python3-opencensus-ext-threading-0.1.2-150100.3.3.3
python3-opentelemetry-api-1.5.0-150100.3.3.3
python3-pytest-3.10.1-150000.7.5.1
python3-pytest-asyncio-0.8.0-150100.3.3.3
python3-websockets-9.1-150100.3.3.3
SUSE Linux Enterprise Module for Public Cloud 15 SP3
azure-cli-core-2.17.1-150100.6.18.1
python3-Deprecated-1.2.13-150100.3.3.3
python3-PyGithub-1.43.5-150100.3.3.3
python3-aiocontextvars-0.2.2-150100.3.3.3
python3-avro-1.11.0-150100.3.3.3
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-opencensus-0.8.0-150100.3.3.3
python3-opencensus-context-0.1.2-150100.3.3.3
python3-opencensus-ext-threading-0.1.2-150100.3.3.3
python3-opentelemetry-api-1.5.0-150100.3.3.3
python3-websockets-9.1-150100.3.3.3
SUSE Linux Enterprise Module for Public Cloud 15 SP4
azure-cli-core-2.17.1-150100.6.18.1
python3-Deprecated-1.2.13-150100.3.3.3
python3-PyGithub-1.43.5-150100.3.3.3
python3-aiocontextvars-0.2.2-150100.3.3.3
python3-avro-1.11.0-150100.3.3.3
python3-cryptography-vectors-3.3.2-150100.3.11.3
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-opencensus-0.8.0-150100.3.3.3
python3-opencensus-context-0.1.2-150100.3.3.3
python3-opencensus-ext-threading-0.1.2-150100.3.3.3
python3-opentelemetry-api-1.5.0-150100.3.3.3
python3-websockets-9.1-150100.3.3.3
SUSE Linux Enterprise Module for Public Cloud 15 SP5
azure-cli-core-2.17.1-150100.6.18.1
python3-humanfriendly-10.0-150100.6.3.3
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
SUSE Linux Enterprise Module for Server Applications 15 SP4
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Module for Server Applications 15 SP5
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Real Time 15 SP3
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Server 15 SP1-LTSS
libprotobuf-lite20-3.9.2-150100.8.3.3
libprotobuf20-3.9.2-150100.8.3.3
libprotoc20-3.9.2-150100.8.3.3
protobuf-devel-3.9.2-150100.8.3.3
python2-cryptography-3.3.2-150100.7.15.3
python2-psutil-5.9.1-150100.6.6.3
python2-requests-2.25.1-150100.6.13.3
python3-Automat-0.6.0-150000.3.4.1
python3-Twisted-17.9.0-150000.3.8.1
python3-constantly-15.1.0-150000.3.4.1
python3-cryptography-3.3.2-150100.7.15.3
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Server 15 SP2-LTSS
python2-psutil-5.9.1-150100.6.6.3
python2-requests-2.25.1-150100.6.13.3
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Server 15 SP3-LTSS
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
libprotobuf-lite20-3.9.2-150100.8.3.3
libprotobuf20-3.9.2-150100.8.3.3
libprotoc20-3.9.2-150100.8.3.3
protobuf-devel-3.9.2-150100.8.3.3
python2-cryptography-3.3.2-150100.7.15.3
python2-psutil-5.9.1-150100.6.6.3
python2-requests-2.25.1-150100.6.13.3
python3-Automat-0.6.0-150000.3.4.1
python3-Twisted-17.9.0-150000.3.8.1
python3-constantly-15.1.0-150000.3.4.1
python3-cryptography-3.3.2-150100.7.15.3
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
python2-psutil-5.9.1-150100.6.6.3
python2-requests-2.25.1-150100.6.13.3
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-psutil-5.9.1-150100.6.6.3
python3-requests-2.25.1-150100.6.13.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Manager Proxy 4.2
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
SUSE Manager Server 4.2
python3-Automat-0.6.0-150000.3.4.1
python3-constantly-15.1.0-150000.3.4.1
python3-hyperlink-17.2.1-150000.3.4.1
python3-incremental-17.5.0-150000.3.4.1
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1
openSUSE Leap 15.4
azure-cli-core-2.17.1-150100.6.18.1
python3-constantly-15.1.0-150000.3.4.1
python3-humanfriendly-10.0-150100.6.3.3
python3-hyperlink-17.2.1-150000.3.4.1
python3-jsondiff-1.3.0-150100.3.6.3
python3-knack-0.9.0-150100.3.7.3
python3-websocket-client-1.3.2-150100.6.7.3
python3-zope.interface-4.4.2-150000.3.4.1

Описание

aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in 5.


Затронутые продукты
Container ses/7.1/cephcsi/cephcsi:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container ses/7.1/rook/ceph:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container suse/sle15:15.1:libprotobuf-lite20-3.9.2-150100.8.3.3
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libprotobuf-lite20-3.9.2-150100.8.3.3

Ссылки

Описание

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.


Затронутые продукты
Container ses/7.1/cephcsi/cephcsi:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container ses/7.1/rook/ceph:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container suse/sle15:15.1:libprotobuf-lite20-3.9.2-150100.8.3.3
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libprotobuf-lite20-3.9.2-150100.8.3.3

Ссылки

Описание

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.


Затронутые продукты
Container ses/7.1/cephcsi/cephcsi:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container ses/7.1/rook/ceph:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container suse/sle15:15.1:libprotobuf-lite20-3.9.2-150100.8.3.3
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libprotobuf-lite20-3.9.2-150100.8.3.3

Ссылки

Описание

An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions.


Затронутые продукты
Container ses/7.1/cephcsi/cephcsi:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container ses/7.1/rook/ceph:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container suse/sle15:15.1:libprotobuf-lite20-3.9.2-150100.8.3.3
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libprotobuf-lite20-3.9.2-150100.8.3.3

Ссылки

Описание

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.


Затронутые продукты
Container ses/7.1/cephcsi/cephcsi:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container ses/7.1/rook/ceph:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container suse/sle15:15.1:libprotobuf-lite20-3.9.2-150100.8.3.3
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libprotobuf-lite20-3.9.2-150100.8.3.3

Ссылки

Описание

A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple key-value per elements creates parsing issues, and can lead to a Denial of Service against services receiving unsanitized input. We recommend upgrading to versions 3.18.3, 3.19.5, 3.20.2, 3.21.6 for protobuf-cpp and 3.18.3, 3.19.5, 3.20.2, 4.21.6 for protobuf-python. Versions for 3.16 and 3.17 are no longer updated.


Затронутые продукты
Container ses/7.1/cephcsi/cephcsi:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container ses/7.1/rook/ceph:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container suse/sle15:15.1:libprotobuf-lite20-3.9.2-150100.8.3.3
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libprotobuf-lite20-3.9.2-150100.8.3.3

Ссылки

Описание

A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in potentially long garbage collection pauses. We recommend updating to the versions mentioned above.


Затронутые продукты
Container ses/7.1/cephcsi/cephcsi:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container ses/7.1/rook/ceph:latest:python3-websocket-client-1.3.2-150100.6.7.3
Container suse/sle15:15.1:libprotobuf-lite20-3.9.2-150100.8.3.3
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production:libprotobuf-lite20-3.9.2-150100.8.3.3

Ссылки
Уязвимость SUSE-SU-2023:2783-1