Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2020:0792-1 Moderate: python-cffi, python-cryptography Update

suse
Calendar Grey March 25, 2020
Dist Suse Esm H88
SUSE Security Patch resolves a significant flaw in python-cffi and python-cryptography. Critical for system administrators.
An update that solves one vulnerability and has 6 fixes is now available

Summary

This update for python-cffi, python-cryptography fixes the following issues: Security issue fixed: - CVE-2018-10903: Fixed GCM tag forgery via truncated tag in finalize_with_tag API (bsc#1101820). Non-security issues fixed: python-cffi was updated to 1.11.2 (bsc#1138748, jsc#ECO-1256, jsc#PM-1598): - fixed a build failure on i586 (bsc#1111657) - Salt was unable to highstate in snapshot 20171129 (bsc#1070737) - Update pytest in spec to add c directory tests in addition to testing directory. - update to version 1.11.2: * Fix Windows issue with managing the thread-state on CPython 3.0 to 3.5 - Update pytest in spec to add c directory tests in addition to testing directory. - Omit test_init_once_multithread tests as they rely on multiple threads finishing in a given time. Returns sporadic pass/fail within build.

References

#1055478 #1070737 #1101820 #1111657 #1138748

#1149792 #981848

Cross- CVE-2018-10903

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP5

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linux Enterprise Server 12-SP3-BCL

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Enterprise Storage 5

SUSE CaaS Platform 3.0

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2018-10903.html

https://bugzilla.suse.com/1055478

https://bugzilla.suse.com/1070737

...

Read the Full Advisory

Announcement ID: SUSE-SU-2020:0792-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here