Upstream details at : https://access.redhat.com/errata/RHSA-2020:0726. CentOS Errata and Security Advisory 2020:0726 Important Upstream details at : https://access.redhat.com/errata/RHSA-2020:0726 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: ed17c727b0327a156d3dc917a95bc1fbf50a03bd6fcaa7f6155c63271b7ade9c sudo-1.8.6p3-29.el6_10.3.i686.rpm 17fd13eb5a39d752ca21fa7a1f0a452c77831cac1646efc232257d1ea31180b5 sudo-devel-1.8.6p3-29.el6_10.3.i686.rpm x86_64: 34dc40c917e4080b159bb3fbea767eeea5d60275b0a3d4f715cde348a24e9886 sudo-1.8.6p3-29.el6_10.3.x86_64.rpm 17fd13eb5a39d752ca21fa7a1f0a452c77831cac1646efc232257d1ea31180b5 sudo-devel-1.8.6p3-29.el6_10.3.i686.rpm 2d709b3d4831234d92105aaa0b7207a41c73432005322781098de926c7ed1d4c sudo-devel-1.8.6p3-29.el6_10.3.x86_64.rpm Source: 7fa30b571a1bcb5762dd8754a17001a71080475b7eb7dffc831ea1f2e6bd809d sudo-1.8.6p3-29.el6_10.3.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
Upstream details at : https://access.redhat.com/errata/RHSA-2018:2918. CentOS Errata and Security Advisory 2018:2918 Important Upstream details at : https://access.redhat.com/errata/RHSA-2018:2918 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: fc0dd921bda357db3e09e73b10301a62d04975b6bce7972161da7c5333811865 ghostscript-9.07-29.el7_5.2.i686.rpm e0096f399f94890fe36f457d5634e0ec23e1123e503c251e8a743dda052cc709 ghostscript-9.07-29.el7_5.2.x86_64.rpm a1aa2003f542e4e2ca01a5ec4c3d333a986c769e9f4c2a6515760a118e344fcb ghostscript-cups-9.07-29.el7_5.2.x86_64.rpm 89e997001ad425a580f2adcca20d4ea4f6c50709e37485e714e4a9a7d2cb3f7c ghostscript-devel-9.07-29.el7_5.2.i686.rpm c6036cc79620d54fa7821b44ab24abb285e9528106a82a69b6583ebb41070f0f ghostscript-devel-9.07-29.el7_5.2.x86_64.rpm 767b833a7ab694de40c2bd571bb1a8d45448453153a8a9d6bb9ac0af7ce04f5f ghostscript-doc-9.07-29.el7_5.2.noarch.rpm 30b711e2e6831a608cab675dfc5d45693e08e9b9653068778582b8dce07b038b ghostscript-gtk-9.07-29.el7_5.2.x86_64.rpm Source: 70c2cf20dcbd109c3bcc79780e3b9c1e06c12eea4f43ee5c5b13b5d86629e540 ghostscript-9.07-29.el7_5.2.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
The textbook ElGamal implementation is not secure. PyCrypto and some other implementations use the wrong algorithm, which may lead to some information disclosure simply by looking at the encrypted text. For a full description, see https://github.com/pycrypto/pycrypto/issues/253 This update includes a fix for this problem backported from pycryptodome.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-913c225b49 2018-02-27 17:16:42.083095 --------------------------------------------------------------------------------Name : python-crypto Product : Fedora 27 Version : 2.6.1 Release : 22.fc27 URL : https://www.pycrypto.org/ Summary : Cryptography library for Python Description : PyCrypto is a collection of both secure hash functions (such as MD5 and SHA), and various encryption algorithms (AES, DES, RSA, ElGamal, etc.). --------------------------------------------------------------------------------Update Information: The textbook ElGamal implementation is not secure. PyCrypto and some other implementations use the wrong algorithm, which may lead to some information disclosure simply by looking at the encrypted text. For a full description, see https://github.com/pycrypto/pycrypto/issues/253 This update includes a fix for this problem backported from pycryptodome. --------------------------------------------------------------------------------References: [ 1 ] Bug #1542313 - CVE-2018-6594 python-crypto: Weak ElGamal key parameters in PublicKey/ElGamal.py allow attackers to obtain sensitive information by reading ciphertext https://bugzilla.redhat.com/show_bug.cgi?id=1542313 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade python-crypto' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.