Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

SUSE: 2020:0790-1 Moderate Vulnerability in Python-Cffi GCM Forgery

suse
Calendar Grey March 25, 2020
Dist Suse Esm H88
Critical SUSE Security Patch Released for Python Packages Targeting Significant Flaw with Multiple Solutions Now Accessible.
An update that solves one vulnerability and has 6 fixes is now available

Summary

This update for python-cffi, python-cryptography and python-xattr fixes the following issues: Security issue fixed: - CVE-2018-10903: Fixed GCM tag forgery via truncated tag in finalize_with_tag API (bsc#1101820). Non-security issues fixed: python-cffi was updated to 1.11.2 (bsc#1138748, jsc#ECO-1256, jsc#PM-1598): - fixed a build failure on i586 (bsc#1111657) - Salt was unable to highstate in snapshot 20171129 (bsc#1070737) - Update pytest in spec to add c directory tests in addition to testing directory. Update to 1.11.1: * Fix tests, remove deprecated C API usage * Fix (hack) for 3.6.0/3.6.1/3.6.2 giving incompatible binary extensions (cpython issue #29943) * Fix for 3.7.0a1+ Update to 1.11.0: * Support the modern standard types char16_t and char32_t. These work like

References

#1055478 #1070737 #1101820 #1111657 #1138748

#1149792 #981848

Cross- CVE-2018-10903

Affected Products:

SUSE OpenStack Cloud 6-LTSS

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP1-LTSS

https://www.suse.com/security/cve/CVE-2018-10903.html

https://bugzilla.suse.com/1055478

https://bugzilla.suse.com/1070737

https://bugzilla.suse.com/1101820

https://bugzilla.suse.com/1111657

https://bugzilla.suse.com/1138748

https://bugzilla.suse.com/1149792

https://bugzilla.suse.com/981848

Announcement ID: SUSE-SU-2020:0790-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here