MGASA-2015-0460
Dashboard / Vulnerabilities / MGASA-2015-0460
MGASA-2015-0460
Summary: Updated python-cryptography packages fix security vulnerability
Details: The OpenSSL backend prior to 1.0.2 made extensive use of assertions to check response codes where our tests could not trigger a failure. However, when Python is run with -O these asserts are optimized away. If a user ran Python with this flag and got an invalid response code this could result in undefined behavior or worse (rhbz#1267548). The python-cryptography and python-cryptography-vectors packages have been updated to version 1.0.2 and python-pyasn1 has been updated to version 0.1.8, fixing this issue.
References: https://advisories.mageia.org/MGASA-2015-0460.html, https://bugs.mageia.org/show_bug.cgi?id=17144, https://lists.fedoraproject.org/pipermail/package-announce/2015-November/171389.html, https://lists.fedoraproject.org/pipermail/package-announce/2015-November/171390.html
Affected packages
Package
Name: python-cryptography
Purl: pkg:rpm/mageia/python-cryptography?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
