UBUNTU-CVE-2022-48566
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-48566
UBUNTU-CVE-2022-48566
Summary:
Details: An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
References: https://ubuntu.com/security/CVE-2022-48566, https://github.com/python/cpython/commit/8183e11d87388e4e44e3242c42085b87a878f781, https://github.com/python/cpython/issues/84968, https://bugs.python.org/issue40791, https://ubuntu.com/security/notices/USN-6400-1, https://www.cve.org/CVERecord?id=CVE-2022-48566, https://ubuntu.com/security/notices/USN-6891-1, https://ubuntu.com/security/notices/USN-7180-1
Affected packages
Package
Name: python3.5
Purl: pkg:deb/ubuntu/python3.5?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
