It was discovered that python-ecdsa, a cryptographic signature library for Python, did not correctly verify DER encoded signatures. Malformed signatures could lead to unexpected exceptions and in some cases did not raise any exception. . Package : python-ecdsa Version : 0.11-1+deb8u1 CVE ID : CVE-2019-14853 CVE-2019-14859 It was discovered that python-ecdsa, a cryptographic signature library for Python, did not correctly verify DER encoded signatures. Malformed signatures could lead to unexpected exceptions and in some cases did not raise any exception. For Debian 8 "Jessie", these problems have been fixed in version 0.11-1+deb8u1. We recommend that you upgrade your python-ecdsa packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance python-ecdsa library versions to resolve problems with improperly formatted DER signatures in Debian LTS distributions.. python-ecdsa, Debian LTS, security update, cryptographic library. . LinuxSecurity.com Team
OpenSSL incorrect checks for malformed signatures https://bugzilla.redhat.com/show_bug.cgi?id=479655. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-0577 2009-01-16 22:38:38 --------------------------------------------------------------------------------Name : nessus-core Product : Fedora 10 Version : 2.2.11 Release : 1.fc10 URL : https://www.tenable.com/ Summary : Network vulnerability scanner Description : Nessus is the world's most popular vulnerability scanner used in over 75,000 organizations world-wide. Many of the world's largest organizations are realizing significant cost savings by using Nessus to audit business-critical enterprise devices and applications. The "Nessus" Project was started by Renaud Deraison in 1998 to provide to the internet community a free, powerful, up-to-date and easy to use remote security scanner. Nessus is currently rated among the top products of its type throughout the security industry and is endorsed by professional information security organizations such as the SANS Institute. --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #479655 - libnasl: OpenSSL incorrect checks for malformed signatures https://bugzilla.redhat.com/show_bug.cgi?id=479655 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update nessus-core' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.