* bsc#1224788 Cross-References: * CVE-2024-35195 . # Security update for python-requests Announcement ID: SUSE-SU-2024:1880-2 Rating: moderate References: * bsc#1224788 Cross-References: * CVE-2024-35195 CVSS scores: * CVE-2024-35195 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-requests fixes the following issues: * CVE-2024-35195: Fixed cert verification regardless of changes to the value of `verify` (bsc#1224788). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2024-1880=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2024-1880=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2024-1880=1 * SUSE Enterprise Storage 7.1 zypper in -t patchSUSE-Storage-7.1-2024-1880=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-1880=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-1880=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-1880=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-1880=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-1880=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-1880=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-1880=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-1880=1 ## Package List: * SUSE Manager Proxy 4.3 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Manager Server 4.3 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Enterprise Storage 7.1 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4(noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * python3-requests-2.25.1-150300.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-requests-2.25.1-150300.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35195.html * https://bugzilla.suse.com/show_bug.cgi?id=1224788 . Bolster your SUSE environment by applying the essential security patch for python-requests, which adeptly tackles certification verification concerns.. SUSE Security Update, Python Requests Fix, SUSE Enterprise Vulnerability, Cert Verification Issue. . LinuxSecurity.com Team
* bsc#1224788 Cross-References: * CVE-2024-35195 . # Security update for python-requests Announcement ID: SUSE-SU-2024:1946-1 Rating: moderate References: * bsc#1224788 Cross-References: * CVE-2024-35195 CVSS scores: * CVE-2024-35195 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N Affected Products: * Advanced Systems Management Module 12 * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Server for the Raspberry Pi 12-SP2 * SUSE Manager Client Tools for SLE 12 An update that solves one vulnerability can now be installed. ## Description: This update for python-requests fixes the following issues: * CVE-2024-35195: Fixed cert verification regardless of changes to the value of `verify` (bsc#1224788). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE 12 zypperin -t patch SUSE-SLE-Manager-Tools-12-2024-1946=1 * Advanced Systems Management Module 12 zypper in -t patch SUSE-SLE-Module-Adv-Systems-Management-12-2024-1946=1 ## Package List: * SUSE Manager Client Tools for SLE 12 (noarch) * python3-requests-2.11.1-6.37.1 * python-requests-2.11.1-6.37.1 * Advanced Systems Management Module 12 (noarch) * python3-requests-2.11.1-6.37.1 * python-requests-2.11.1-6.37.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35195.html * https://bugzilla.suse.com/show_bug.cgi?id=1224788 . The python-requests library has updated to fix the security vulnerability CVE-2024-35195, rated moderate risk, enhancing certificate verification for better security. SUSE Update, Python Requests, Security Fix, Cert Verification, Software Security. . Severity: Important. LinuxSecurity.com Team
Update to the upstream 3.7.1 release, which includes fixes for CVE-2021-20231 and CVE-2021-20232, fipscheck build-dep removal, and TLS 1.3 middlebox compatibility mode fixes. ---- Fix cert chain verification if it contains duplicate certs.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-18bef34f05 2021-03-24 01:46:57.845776 --------------------------------------------------------------------------------Name : gnutls Product : Fedora 34 Version : 3.7.1 Release : 2.fc34 URL : http://www.gnutls.org/ Summary : A TLS protocol implementation Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. --------------------------------------------------------------------------------Update Information: Update to the upstream 3.7.1 release, which includes fixes for CVE-2021-20231 and CVE-2021-20232, fipscheck build-dep removal, and TLS 1.3 middlebox compatibility mode fixes. ---- Fix cert chain verification if it contains duplicate certs. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 16 2021 Daiki Ueno - 3.7.1-2 - Restore fipscheck dependency * Sat Mar 13 2021 Daiki Ueno - 3.7.1-1 - Update to upstream 3.7.1 release - Remove fipscheck dependency, as it is now calculated with an internal tool * Fri Mar 5 2021 Daiki Ueno - 3.7.0-4 - Tolerate duplicate certs in the chain also with PKCS #11 trust store * Tue Mar 2 2021 Daiki Ueno - 3.7.0-3 - Reduce BRs for non-bootstrapping build --------------------------------------------------------------------------------References: [ 1 ] Bug #1903554 - gnutls-3.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1903554 [ 2 ] Bug #1938147 - CVE-2021-20231 gnutls: Use after free in client key_share extension [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1938147 [ 3 ] Bug #1938149 - CVE-2021-20232 gnutls: Use after free in client_send_params in lib/ext/pre_shared_key.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1938149 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-18bef34f05' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.