SUSE-RU-2018:4074-1

    Dashboard / Vulnerabilities / SUSE-RU-2018:4074-1

    SUSE-RU-2018:4074-1

    Published: 11 Dec 2018Last Modified: 4 Feb 2026
    Upstream:

    Summary: Recommended update for aws-cli, python-boto3, python-botocore, python-s3transfer

    Details: This update for aws-cli, python-boto3, python-botocore, python-s3transfer fixes the following issues: aws-cli: - Update to version 1.16.61. (bsc#1088310) + For detailed changes see https://github.com/aws/aws-cli/blob/1.16.1/CHANGELOG.rst - Update to version 1.16.1 (bsc#1105988, bsc#1092493) + CVE-2018-15869: An Amazon Web Services (AWS) developer who does not specify the --owners flag when describing images via AWS CLI, and therefore not properly validating source software per AWS recommended security best practices, might have unintentionally loaded an undesired and potentially malicious Amazon Machine Image (AMI) from the uncurated public community AMI catalog. - Disable vendored versions of requests and six from botocore and use requests and six from the RPM packages. python-botocore: - Update to version 1.10.40 + For detailed changes, please refer to the changelog. + Remove the broken attempt to avoid using the bundeled requests module provided by the source (bsc#1088310) python-boto3: - Version update to 1.9.57 (bsc#1118021, bsc#1118027) + For detailed changes, please refer to the changelog. python-s3transfer: - Update to version 0.1.13 - Make sure to really not use any bundles. - enhancement:max_bandwidth: Add ability to set maximum bandwidth consumption for streaming of S3 uploads and downloads.

    Affected packages

    Package

    Name: python-boto3

    Purl: pkg:rpm/suse/python-boto3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.9.57-3.5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High