Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2023:1838-1 Moderate: Python-Crcmod Buffer Overflow Risk

suse
Calendar Grey February 27, 2024
Dist Suse Esm H88
SUSE distributions have released a security update addressing vulnerabilities in python-crcmod and python-cryptography, ensuring enhanced protection and relevant patches implemented.
* bsc#1177083 * bsc#1181995 * jsc#ECO-3329 * jsc#PM-2475 * jsc#PM-2730

Summary

## This update for python-crcmod, python-cryptography, python-cryptography-vectors contains the following fixes: Changes in python-crcmod: * Include in SLE-15 (bsc#1177083, jsc#PM-2730, jsc#SLE-18312) * Include in SLE-15 (bsc#1181995, jsc#ECO-3329, jsc#PM-2475) * Cleanup spec file * Use fdupes * Do not bundle html doc * singlespec auto-conversion * Include in SLE 12 (FATE #316168) * Initial release Changes in python-cryptography: \- Update in SLE-15 (bsc#1177083, jsc#PM-2730, jsc#SLE-18312) * Refresh patches for new version * Using the Fernet class to symmetrically encrypt multi gigabyte values. (bsc#1182066, CVE-2020-36242) could result in an integer overflow and buffer overflow. * update to 2.9.2 * 2.9.2 - 2020-04-22

References

* bsc#1177083

* bsc#1181995

* jsc#ECO-3329

* jsc#PM-2475

* jsc#PM-2730

* jsc#SLE-18312

Affected Products:

* openSUSE Leap 15.4

* Public Cloud Module 15-SP2

* Public Cloud Module 15-SP1

* Public Cloud Module 15-SP3

* Public Cloud Module 15-SP4

* SUSE Linux Enterprise High Performance Computing 15 SP1

* SUSE Linux Enterprise High Performance Computing 15 SP2

* SUSE Linux Enterprise High Performance Computing 15 SP3

* SUSE Linux Enterprise High Performance Computing 15 SP4

* SUSE Linux Enterprise Server 15 SP1

* SUSE Linux Enterprise Server 15 SP2

* SUSE Linux Enterprise Server 15 SP3

* SUSE Linux Enterprise Server 15 SP4

* SUSE Linux Enterprise Server for SAP Applications 15 SP1

* SUSE Linux Enterprise Server for SAP Applications 15 SP2

* SUSE Linux Enterprise Server for SAP Applications 15 SP3

Announcement ID: SUSE-SU-2023:1838-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here