Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Warning: Undefined array key "Description" in /var/www/www.linuxsecurity.com-443/html/lsadvisories/lsadvisories.php on line 220

Fedora 22: 2016-c845706426 Critical: Python-RSA Signature Forgery

fedora
Calendar Grey January 24, 2016
Dist Fedora Esm H88
Fedora 22 enhances python-rsa to address a severe signature spoofing flaw identified in CVE-2016-1494, which has the potential to compromise security.
Fix for CVE-2016-1494

Summary

Python-RSA is a pure-Python RSA implementation. It supports encryption

and decryption, signing and verifying signatures, and key generation

according to PKCS#1 version 1.5. It can be used as a Python library as

well as on the command-line.

Update Information:

Fix for CVE-2016-1494

Change Log

References


[ 1 ] Bug #1295871 - CVE-2016-1494 python-rsa: Signature forgery using Bleichenbacher'06 attack [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1295871 [ 2 ] Bug #1295870 - CVE-2016-1494 python-rsa: Signature forgery using Bleichenbacher'06 attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1295870 [ 3 ] Bug #1298335 - python-rsa-3.2.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1298335 [ 4 ] Bug #1297222 - Old version with security issues, please approve ACL https://bugzilla.redhat.com/show_bug.cgi?id=1297222

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update python-rsa' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-rsa
Product: Fedora 22
Version: 3.3
Release: 2.fc22
Summary: Pure-Python RSA implementation

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here