Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE 15.3: 2021:2817-1 Moderate: AWS-CLI Python CRLF Injection

opensuse
Calendar Grey August 23, 2021
Dist Opensuse Esm H88
An important announcement for Fedora patching a significant SQL injection vulnerability in Ruby libraries, enhancing overall platform integrity.
An update that solves one vulnerability, contains two features and has 6 fixes is now available

Description

This patch updates the Python AWS SDK stack in SLE 15:

General:

# aws-cli

- Version updated to upstream release v1.19.9 For a detailed list of all

changes, please refer to the changelog file of this package.

# python-boto3

- Version updated to upstream release 1.17.9 For a detailed list of all

changes, please refer to the changelog file of this package.

# python-botocore

- Version updated to upstream release 1.20.9 For a detailed list of all

changes, please refer to the changelog file of this package.

# python-urllib3

- Version updated to upstream release 1.25.10 For a detailed list of all

changes, please refer to the changelog file of this package.

# python-service_identity

- Added this new package to resolve runtime dependencies for other

packages. Version: 18.1.0

# python-trustme

- Added this new package to resolve runtime dependencies for other

packages. Version: 0.6.0

Security fixes:

#...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-2817=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

python-cffi-debuginfo-1.13.2-3.2.5

python-cffi-debugsource-1.13.2-3.2.5

python-cryptography-debuginfo-2.8-10.1

python-cryptography-debugsource-2.8-10.1

python2-cffi-1.13.2-3.2.5

python2-cffi-debuginfo-1.13.2-3.2.5

python2-cryptography-2.8-10.1

python2-cryptography-debuginfo-2.8-10.1

python3-cffi-1.13.2-3.2.5

python3-cffi-debuginfo-1.13.2-3.2.5

python3-cryptography-2.8-10.1

python3-cryptography-debuginfo-2.8-10.1

- openSUSE Leap 15.3 (noarch):

aws-cli-1.19.9-26.1

python2-asn1crypto-0.24.0-3.2.1

python2-boto3-1.17.9-19.1

python2-botocore-1.20.9-33.1

python2-pyasn1-0.4.2-3.2.1

python2-pycparser-2.17-3.2.1

python2-urllib3-1.25.10-9.14.1

python3-asn1crypto-0.24.0-3.2.1

python3-boto3-1.17.9-19.1

python3-botocore-1.20.9-33.1

python3-pyasn1-0.4.2-3.2.1

python3-pycparser-2.17-3.2.1

References

https://www.suse.com/security/cve/CVE-2020-26137.html

https://bugzilla.suse.com/1102408

https://bugzilla.suse.com/1138715

https://bugzilla.suse.com/1138746

https://bugzilla.suse.com/1176389

https://bugzilla.suse.com/1177120

https://bugzilla.suse.com/1182421

https://bugzilla.suse.com/1182422

Announcement ID: openSUSE-SU-2021:2817-1
Rating: moderate
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here