Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:1206-1

Опубликовано: 27 авг. 2021
Источник: suse-cvrf

Описание

Security update for aws-cli, python-boto3, python-botocore, python-service_identity, python-trustme, python-urllib3

This patch updates the Python AWS SDK stack in SLE 15:

General:

aws-cli

  • Version updated to upstream release v1.19.9 For a detailed list of all changes, please refer to the changelog file of this package.

python-boto3

  • Version updated to upstream release 1.17.9 For a detailed list of all changes, please refer to the changelog file of this package.

python-botocore

  • Version updated to upstream release 1.20.9 For a detailed list of all changes, please refer to the changelog file of this package.

python-urllib3

  • Version updated to upstream release 1.25.10 For a detailed list of all changes, please refer to the changelog file of this package.

python-service_identity

  • Added this new package to resolve runtime dependencies for other packages. Version: 18.1.0

python-trustme

  • Added this new package to resolve runtime dependencies for other packages. Version: 0.6.0

Security fixes:

python-urllib3:

  • CVE-2020-26137: urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest() (bsc#1177120)

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Список пакетов

openSUSE Leap 15.2
python-pyOpenSSL-doc-17.5.0-lp152.7.3.1
python2-cffi-1.13.2-lp152.2.3.1
python2-cryptography-2.8-lp152.2.12.1
python2-pyOpenSSL-17.5.0-lp152.7.3.1
python3-cffi-1.13.2-lp152.2.3.1
python3-cryptography-2.8-lp152.2.12.1
python3-pyOpenSSL-17.5.0-lp152.7.3.1

Описание

urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.


Затронутые продукты
openSUSE Leap 15.2:python-pyOpenSSL-doc-17.5.0-lp152.7.3.1
openSUSE Leap 15.2:python2-cffi-1.13.2-lp152.2.3.1
openSUSE Leap 15.2:python2-cryptography-2.8-lp152.2.12.1
openSUSE Leap 15.2:python2-pyOpenSSL-17.5.0-lp152.7.3.1

Ссылки
Уязвимость openSUSE-SU-2021:1206-1