Bleichenbacher timing attacks in the RSA decryption API (CVE-2020-25657) References: - https://bugs.mageia.org/show_bug.cgi?id=30661 - https://lists.suse.com/pipermail/sle-security-updates/2022-July/011631.html . MGASA-2022-0274 - Updated python-m2crypto packages fix security vulnerability Publication date: 05 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0274.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-25657 Bleichenbacher timing attacks in the RSA decryption API (CVE-2020-25657) References: - https://bugs.mageia.org/show_bug.cgi?id=30661 - https://lists.suse.com/pipermail/sle-security-updates/2022-July/011631.html - - https://www.cve.org/CVERecord?id=CVE-2020-25657 SRPMS: - 8/core/python-m2crypto-0.38.0-4.mga8 . Recent updates to the python-m2crypto packages have effectively mitigated the Bleichenbacher timing attacks impacting the RSA decryption API on Mageia 8.. Bleichenbacher Attack, Python Security Update, Mageia Advisory. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-cryptography ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3592-1 Rating: moderate References: #1178168 Cross-References: CVE-2020-25659 Affected Products: SUSE Linux Enterprise Module for Python2 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-cryptography fixes the following issues: - CVE-2020-25659: Attempted to mitigate Bleichenbacher attacks on RSA decryption (bsc#1178168). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Python2 15-SP2: zypper in -t patch SUSE-SLE-Module-Python2-15-SP2-2020-3592=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-3592=1 Package List: - SUSE Linux Enterprise Module for Python2 15-SP2 (aarch64 ppc64le s390x x86_64): python-cryptography-debuginfo-2.8-3.3.1 python-cryptography-debugsource-2.8-3.3.1 python2-cryptography-2.8-3.3.1 python2-cryptography-debuginfo-2.8-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): python-cryptography-debuginfo-2.8-3.3.1 python-cryptography-debugsource-2.8-3.3.1 python3-cryptography-2.8-3.3.1 python3-cryptography-debuginfo-2.8-3.3.1 References: https://www.suse.com/security/cve/CVE-2020-25659.html https://bugzilla.suse.com/1178168 . The latest release of python-cryptography mitigates a notable vulnerabilityrelated to Bleichenbacher exploits targeting RSA decryption mechanisms.. SUSE Python Update, Cryptography Security Patch, python-cryptography Fix. . LinuxSecurity.com Team
Cache side-channel variant of the Bleichenbacher attack.(CVE-2018-12404) References: - https://bugs.mageia.org/show_bug.cgi?id=23972 - . MGASA-2018-0482 - Updated nss packages fix security vulnerability Publication date: 15 Dec 2018 URL: https://advisories.mageia.org/MGASA-2018-0482.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-12404 Cache side-channel variant of the Bleichenbacher attack.(CVE-2018-12404) References: - https://bugs.mageia.org/show_bug.cgi?id=23972 - - https://www.cve.org/CVERecord?id=CVE-2018-12404 SRPMS: - 6/core/nss-3.36.6-1.mga6 - 6/core/rootcerts-20181108.00-1.mga6 . Mageia 2018-0483 tackles a critical vulnerability related to a Bleichenbacher-style assault. Discover the solutions and their implications.. mageia security, nss update, bleichenbacher attack, side-channel exploit, security advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.