An update that solves one vulnerability can now be installed.. # Security update for python-cryptography Announcement ID: SUSE-SU-2026:20706-1 Release Date: 2026-03-05T13:16:19Z Rating: moderate References: * bsc#1258074 Cross-References: * CVE-2026-26007 CVSS scores: * CVE-2026-26007 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-26007 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-26007 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-26007 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2026-26007: missing validation can lead to security issues for signature verification (ECDSA) and shared key negotiation (ECDH) (bsc#1258074). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-607=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * python311-cryptography-42.0.4-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26007.html * https://bugzilla.suse.com/show_bug.cgi?id=1258074 . Critical update for python-cryptography on SUSE addressing security issues with signature verification and key negotiation.. SUSE Linux Micro, python-cryptography, security update, CVE-2026-26007, moderate severity. . Severity: Important. LinuxSecurity.com Team
Juray Sarinay discovered that PDF documents signed with the adbe.pkcs7.sha1 standard were incompletely validated by LibreOffice, which could cause invalid signatures to be accepted as legitimate. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5908-1
An update for libreoffice is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libreoffice security update Advisory ID: RHSA-2022:7461-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7461 Issue date: 2022-11-08 CVE Names: CVE-2021-25636 ==================================================================== 1. Summary: An update for libreoffice is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - ppc64le, x86_64 Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite. Security Fix(es): * libreoffice: Incorrect trust validation of signature with ambiguous KeyInfo children (CVE-2021-25636) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information onchanges in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of LibreOffice applications must be restarted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2056955 - CVE-2021-25636 libreoffice: Incorrect trust validation of signature with ambiguous KeyInfo children 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: libreoffice-6.4.7.2-11.el8.src.rpm aarch64: libreoffice-base-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-calc-6.4.7.2-11.el8.aarch64.rpm libreoffice-calc-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-core-6.4.7.2-11.el8.aarch64.rpm libreoffice-core-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-debugsource-6.4.7.2-11.el8.aarch64.rpm libreoffice-glade-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-graphicfilter-6.4.7.2-11.el8.aarch64.rpm libreoffice-graphicfilter-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-gtk3-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-help-en-6.4.7.2-11.el8.aarch64.rpm libreoffice-impress-6.4.7.2-11.el8.aarch64.rpm libreoffice-impress-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-langpack-en-6.4.7.2-11.el8.aarch64.rpm libreoffice-officebean-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-ogltrans-6.4.7.2-11.el8.aarch64.rpm libreoffice-ogltrans-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-pdfimport-6.4.7.2-11.el8.aarch64.rpm libreoffice-pdfimport-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-postgresql-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-pyuno-6.4.7.2-11.el8.aarch64.rpm libreoffice-pyuno-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-sdk-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-ure-6.4.7.2-11.el8.aarch64.rpm libreoffice-ure-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-writer-6.4.7.2-11.el8.aarch64.rpm libreoffice-writer-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreoffice-x11-debuginfo-6.4.7.2-11.el8.aarch64.rpm libreofficekit-debuginfo-6.4.7.2-11.el8.aarch64.rpm noarch: autocorr-af-6.4.7.2-11.el8.noarch.rpm autocorr-bg-6.4.7.2-11.el8.noarch.rpm autocorr-ca-6.4.7.2-11.el8.noarch.rpm autocorr-cs-6.4.7.2-11.el8.noarch.rpm autocorr-da-6.4.7.2-11.el8.noarch.rpm autocorr-de-6.4.7.2-11.el8.noarch.rpm autocorr-en-6.4.7.2-11.el8.noarch.rpm autocorr-es-6.4.7.2-11.el8.noarch.rpm autocorr-fa-6.4.7.2-11.el8.noarch.rpm autocorr-fi-6.4.7.2-11.el8.noarch.rpm autocorr-fr-6.4.7.2-11.el8.noarch.rpm autocorr-ga-6.4.7.2-11.el8.noarch.rpm autocorr-hr-6.4.7.2-11.el8.noarch.rpm autocorr-hu-6.4.7.2-11.el8.noarch.rpm autocorr-is-6.4.7.2-11.el8.noarch.rpm autocorr-it-6.4.7.2-11.el8.noarch.rpm autocorr-ja-6.4.7.2-11.el8.noarch.rpm autocorr-ko-6.4.7.2-11.el8.noarch.rpm autocorr-lb-6.4.7.2-11.el8.noarch.rpm autocorr-lt-6.4.7.2-11.el8.noarch.rpm autocorr-mn-6.4.7.2-11.el8.noarch.rpm autocorr-nl-6.4.7.2-11.el8.noarch.rpm autocorr-pl-6.4.7.2-11.el8.noarch.rpm autocorr-pt-6.4.7.2-11.el8.noarch.rpm autocorr-ro-6.4.7.2-11.el8.noarch.rpm autocorr-ru-6.4.7.2-11.el8.noarch.rpm autocorr-sk-6.4.7.2-11.el8.noarch.rpm autocorr-sl-6.4.7.2-11.el8.noarch.rpm autocorr-sr-6.4.7.2-11.el8.noarch.rpm autocorr-sv-6.4.7.2-11.el8.noarch.rpm autocorr-tr-6.4.7.2-11.el8.noarch.rpm autocorr-vi-6.4.7.2-11.el8.noarch.rpm autocorr-zh-6.4.7.2-11.el8.noarch.rpm libreoffice-data-6.4.7.2-11.el8.noarch.rpm libreoffice-opensymbol-fonts-6.4.7.2-11.el8.noarch.rpm libreoffice-ure-common-6.4.7.2-11.el8.noarch.rpm ppc64le: libreoffice-base-6.4.7.2-11.el8.ppc64le.rpm libreoffice-base-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-calc-6.4.7.2-11.el8.ppc64le.rpm libreoffice-calc-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-core-6.4.7.2-11.el8.ppc64le.rpm libreoffice-core-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-debugsource-6.4.7.2-11.el8.ppc64le.rpm libreoffice-draw-6.4.7.2-11.el8.ppc64le.rpm libreoffice-emailmerge-6.4.7.2-11.el8.ppc64le.rpm libreoffice-filters-6.4.7.2-11.el8.ppc64le.rpm libreoffice-gdb-debug-support-6.4.7.2-11.el8.ppc64le.rpm libreoffice-glade-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-graphicfilter-6.4.7.2-11.el8.ppc64le.rpm libreoffice-graphicfilter-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-gtk3-6.4.7.2-11.el8.ppc64le.rpm libreoffice-gtk3-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-ar-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-bg-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-bn-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-ca-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-cs-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-da-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-de-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-dz-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-el-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-en-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-es-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-et-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-eu-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-fi-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-fr-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-gl-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-gu-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-he-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-hi-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-hr-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-hu-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-id-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-it-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-ja-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-ko-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-lt-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-lv-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-nb-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-nl-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-nn-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-pl-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-pt-BR-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-pt-PT-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-ro-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-ru-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-si-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-sk-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-sl-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-sv-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-ta-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-tr-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-uk-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-zh-Hans-6.4.7.2-11.el8.ppc64le.rpm libreoffice-help-zh-Hant-6.4.7.2-11.el8.ppc64le.rpm libreoffice-impress-6.4.7.2-11.el8.ppc64le.rpm libreoffice-impress-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-langpack-en-6.4.7.2-11.el8.ppc64le.rpm libreoffice-math-6.4.7.2-11.el8.ppc64le.rpm libreoffice-officebean-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-ogltrans-6.4.7.2-11.el8.ppc64le.rpm libreoffice-ogltrans-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-pdfimport-6.4.7.2-11.el8.ppc64le.rpm libreoffice-pdfimport-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-postgresql-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-pyuno-6.4.7.2-11.el8.ppc64le.rpm libreoffice-pyuno-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-sdk-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-ure-6.4.7.2-11.el8.ppc64le.rpm libreoffice-ure-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-wiki-publisher-6.4.7.2-11.el8.ppc64le.rpm libreoffice-writer-6.4.7.2-11.el8.ppc64le.rpm libreoffice-writer-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-x11-6.4.7.2-11.el8.ppc64le.rpm libreoffice-x11-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-xsltfilter-6.4.7.2-11.el8.ppc64le.rpm libreofficekit-6.4.7.2-11.el8.ppc64le.rpm libreofficekit-debuginfo-6.4.7.2-11.el8.ppc64le.rpm s390x: libreoffice-base-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-calc-6.4.7.2-11.el8.s390x.rpm libreoffice-calc-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-core-6.4.7.2-11.el8.s390x.rpm libreoffice-core-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-debugsource-6.4.7.2-11.el8.s390x.rpm libreoffice-glade-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-graphicfilter-6.4.7.2-11.el8.s390x.rpm libreoffice-graphicfilter-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-gtk3-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-help-en-6.4.7.2-11.el8.s390x.rpm libreoffice-impress-6.4.7.2-11.el8.s390x.rpm libreoffice-impress-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-langpack-en-6.4.7.2-11.el8.s390x.rpm libreoffice-officebean-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-ogltrans-6.4.7.2-11.el8.s390x.rpm libreoffice-ogltrans-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-pdfimport-6.4.7.2-11.el8.s390x.rpm libreoffice-pdfimport-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-postgresql-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-pyuno-6.4.7.2-11.el8.s390x.rpm libreoffice-pyuno-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-sdk-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-ure-6.4.7.2-11.el8.s390x.rpm libreoffice-ure-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-writer-6.4.7.2-11.el8.s390x.rpm libreoffice-writer-debuginfo-6.4.7.2-11.el8.s390x.rpm libreoffice-x11-debuginfo-6.4.7.2-11.el8.s390x.rpm libreofficekit-debuginfo-6.4.7.2-11.el8.s390x.rpm x86_64: libreoffice-base-6.4.7.2-11.el8.x86_64.rpm libreoffice-base-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-calc-6.4.7.2-11.el8.x86_64.rpm libreoffice-calc-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-core-6.4.7.2-11.el8.x86_64.rpm libreoffice-core-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-debugsource-6.4.7.2-11.el8.x86_64.rpm libreoffice-draw-6.4.7.2-11.el8.x86_64.rpm libreoffice-emailmerge-6.4.7.2-11.el8.x86_64.rpm libreoffice-filters-6.4.7.2-11.el8.x86_64.rpm libreoffice-gdb-debug-support-6.4.7.2-11.el8.x86_64.rpm libreoffice-glade-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-graphicfilter-6.4.7.2-11.el8.x86_64.rpm libreoffice-graphicfilter-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-gtk3-6.4.7.2-11.el8.x86_64.rpm libreoffice-gtk3-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-ar-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-bg-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-bn-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-ca-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-cs-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-da-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-de-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-dz-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-el-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-en-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-es-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-et-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-eu-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-fi-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-fr-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-gl-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-gu-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-he-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-hi-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-hr-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-hu-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-id-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-it-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-ja-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-ko-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-lt-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-lv-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-nb-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-nl-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-nn-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-pl-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-pt-BR-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-pt-PT-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-ro-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-ru-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-si-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-sk-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-sl-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-sv-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-ta-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-tr-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-uk-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-zh-Hans-6.4.7.2-11.el8.x86_64.rpm libreoffice-help-zh-Hant-6.4.7.2-11.el8.x86_64.rpm libreoffice-impress-6.4.7.2-11.el8.x86_64.rpm libreoffice-impress-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-af-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ar-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-as-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-bg-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-bn-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-br-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ca-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-cs-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-cy-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-da-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-de-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-dz-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-el-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-en-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-es-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-et-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-eu-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-fa-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-fi-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-fr-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ga-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-gl-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-gu-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-he-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-hi-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-hr-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-hu-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-id-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-it-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ja-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-kk-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-kn-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ko-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-lt-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-lv-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-mai-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ml-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-mr-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-nb-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-nl-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-nn-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-nr-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-nso-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-or-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-pa-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-pl-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-pt-BR-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-pt-PT-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ro-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ru-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-si-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-sk-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-sl-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-sr-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ss-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-st-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-sv-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ta-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-te-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-th-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-tn-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-tr-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ts-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-uk-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-ve-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-xh-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-zh-Hans-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-zh-Hant-6.4.7.2-11.el8.x86_64.rpm libreoffice-langpack-zu-6.4.7.2-11.el8.x86_64.rpm libreoffice-math-6.4.7.2-11.el8.x86_64.rpm libreoffice-officebean-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-ogltrans-6.4.7.2-11.el8.x86_64.rpm libreoffice-ogltrans-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-pdfimport-6.4.7.2-11.el8.x86_64.rpm libreoffice-pdfimport-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-postgresql-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-pyuno-6.4.7.2-11.el8.x86_64.rpm libreoffice-pyuno-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-sdk-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-ure-6.4.7.2-11.el8.x86_64.rpm libreoffice-ure-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-wiki-publisher-6.4.7.2-11.el8.x86_64.rpm libreoffice-writer-6.4.7.2-11.el8.x86_64.rpm libreoffice-writer-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-x11-6.4.7.2-11.el8.x86_64.rpm libreoffice-x11-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-xsltfilter-6.4.7.2-11.el8.x86_64.rpm libreofficekit-6.4.7.2-11.el8.x86_64.rpm libreofficekit-debuginfo-6.4.7.2-11.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v.8): ppc64le: libreoffice-base-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-calc-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-core-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-debugsource-6.4.7.2-11.el8.ppc64le.rpm libreoffice-glade-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-graphicfilter-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-gtk3-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-impress-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-officebean-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-ogltrans-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-pdfimport-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-postgresql-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-pyuno-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-sdk-6.4.7.2-11.el8.ppc64le.rpm libreoffice-sdk-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-sdk-doc-6.4.7.2-11.el8.ppc64le.rpm libreoffice-ure-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-writer-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreoffice-x11-debuginfo-6.4.7.2-11.el8.ppc64le.rpm libreofficekit-debuginfo-6.4.7.2-11.el8.ppc64le.rpm x86_64: libreoffice-base-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-calc-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-core-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-debugsource-6.4.7.2-11.el8.x86_64.rpm libreoffice-glade-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-graphicfilter-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-gtk3-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-impress-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-officebean-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-ogltrans-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-pdfimport-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-postgresql-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-pyuno-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-sdk-6.4.7.2-11.el8.x86_64.rpm libreoffice-sdk-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-sdk-doc-6.4.7.2-11.el8.x86_64.rpm libreoffice-ure-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-writer-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreoffice-x11-debuginfo-6.4.7.2-11.el8.x86_64.rpm libreofficekit-debuginfo-6.4.7.2-11.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-25636 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.7_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY2pSpdzjgjWX9erEAQjgvBAAo+xK6erK6QOoWXpTivb3tVzYNJ7AZ0p6 yFtmjkplijlVelDnjQS1i7P08o+QS44+uCsmqhmF2qkkYd8fISqzXnB/QUGhleLm gQFwBgjPVGz5hc81EzD1Gmv4MqzbVylHI0AoZHAnmcMT7O3IMDm/F+bbOO22RbEk 1CNW0RyMecsdDPVGSq4vh5HPtGcyL0ZhXFFoq8m14VA3Z0gMb0RDDps2uuCVYAzI Ezb0EdpB/kPFeAMgxmiOW/Usbc9TuJGMY3g4a02zYM6rrnSl7TvrEsbHe/tu4PAD OuT9CStaUTmSMFuzKg06qaHIfdkuPZFZefNekJ/KtOQcDGcVhbn0t1gLbgE454PJ 1sTYb4PKTRfTz+mYuClZs6kSvLiyVPxX7OxGcv4c1tCBRJ62h9dhaHOhP4VZIgnA LJGuB53nGHfOp6Y/lAxMSpoCgs5t4r+e4zUsvP3iJ7+f3sYlYG1QmaYBWWGPkexs SHHDzp/3CK6E2cJf/d4jNO3j/OhC9fvq+Kudr8H0Uqx0DpsYvIlbxSYANE+tdd5k zwSHIlKvf9ErAk2Lqt6pnLDWupIkgf3bN3uH3i+SmsOP1uZ88R3DHS1TK3gKHdCR PRp4TruRN/ipJM0ac7cbazu5blFRu3JBkfgCx6mx+jn+1ohuYckeXqB0qwgtoGTx LEbrqJ7ewJA=XUD3 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
PySAML2 could be made to accept invalid SAML documents.. =========================================================================Ubuntu Security Notice USN-5066-1 September 08, 2021 python-pysaml2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: PySAML2 could be made to accept invalid SAML documents. Software Description: - python-pysaml2: Pure python implementation of SAML2 Details: Brian Wolff discovered that PySAML2 incorrectly validated cryptographic signatures. A remote attacker could possibly use this issue to alter SAML documents. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: python3-pysaml2 6.1.0-0ubuntu1.21.04.1 Ubuntu 20.04 LTS: python3-pysaml2 4.9.0-0ubuntu3.1 Ubuntu 18.04 LTS: python-pysaml2 4.0.2-0ubuntu3.2 python3-pysaml2 4.0.2-0ubuntu3.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5066-1 CVE-2021-21239 Package Information: https://launchpad.net/ubuntu/+source/python-pysaml2/6.1.0-0ubuntu1.21.04.1 https://launchpad.net/ubuntu/+source/python-pysaml2/4.9.0-0ubuntu3.1 https://launchpad.net/ubuntu/+source/python-pysaml2/4.0.2-0ubuntu3.2 . A vulnerability in python-pysaml2 permits erroneous SAML documents, impacting Ubuntu versions 21.04, 20.04 LTS, and 18.04 LTS.. python-pysaml2, SAML vulnerability, Ubuntu security. . Severity: Important. LinuxSecurity.com Team
Fix validation logic in the base consumer The base consumer is intended to only derive its validation switch from the on-disk configuration if the child class doesn't override the validate_signatures switch. There was a bug here where the default value provided in the base class made it appear as if *all* child consumers had turned *off* validation, which is incorrect. This fix turns on. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-fff6e1af37 2017-01-24 19:30:37.937615 -------------------------------------------------------------------------------- Name : fedmsg Product : Fedora 25 Version : 0.18.2 Release : 1.fc25 URL : https://github.com/fedora-infra/fedmsg Summary : Tools for Fedora Infrastructure real-time messaging Description : Python API used around Fedora Infrastructure to send and receive messages with zeromq. Includes some CLI tools. -------------------------------------------------------------------------------- Update Information: Fix validation logic in the base consumer The base consumer is intended to only derive its validation switch from the on-disk configuration if the child class doesn't override the validate_signatures switch. There was a bug here where the default value provided in the base class made it appear as if *all* child consumers had turned *off* validation, which is incorrect. This fix turns on signature validation by default while preserving the ability of child consumersto override the on-disk configuration in special cases. - Fixes: CVE-2017-1000001 - Reviewed-by: Patrick Uiterwijk -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade fedmsg' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
### v1.10.3 / v2.3.3 - This is a security release fixing an issue with signature validation. Please upgrade as soon as possible. - [201612-01](https://simplesamlphp.org/security/201612-01). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-b000091725 2016-12-12 20:34:17.077621 -------------------------------------------------------------------------------- Name : php-simplesamlphp-saml2 Product : Fedora 24 Version : 2.3.3 Release : 1.fc24 URL : https://github.com/simplesamlphp/saml2 Summary : SAML2 PHP library from SimpleSAMLphp Description : A PHP library for SAML2 related functionality. Extracted from SimpleSAMLphp [1], used by OpenConext [2]. This library started as a collaboration between UNINETT [3] and SURFnet [4] but everyone is invited to contribute. Autoloader: /usr/share/php/SAML2/autoload.php [1] https://simplesamlphp.org/ [2] https://openconext.org/ [3] https://sikt.no/ [4] https://www.surf.nl -------------------------------------------------------------------------------- Update Information: ### v1.10.3 / v2.3.3 - This is a security release fixing an issue with signature validation. Please upgrade as soon as possible. - [201612-01](https://simplesamlphp.org/security/201612-01) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1401147 - php-simplesamlphp-saml2-2.3.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1401147 [ 2 ] Bug #1401148 - php-simplesamlphp-saml2_1-1.10.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1401148 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade php-simplesamlphp-saml2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
The version of gnupg that was distributed in Debian GNU/Linux 2.2 hada logic error in the code that checks for valid signatures which couldcause false positive results: . - ------------------------------------------------------------------------Debian Security Advisory
Get the latest Linux and open source security news straight to your inbox.