UbuntuUpdates.org

Package "python-openssl"

Name: python-openssl

Description:

Python 2 wrapper around the OpenSSL library

Latest version: 0.15.1-2ubuntu0.2
Release: xenial (16.04)
Level: security
Repository: main
Head package: pyopenssl
Homepage: https://github.com/pyca/pyopenssl

Links


Download "python-openssl"


Other versions of "python-openssl" in Xenial

Repository Area Version
base main 0.15.1-2build1
updates main 0.15.1-2ubuntu0.2

Changelog

Version: 0.15.1-2ubuntu0.2 2018-11-08 15:07:03 UTC

  pyopenssl (0.15.1-2ubuntu0.2) xenial-security; urgency=medium

  * SECURITY UPDATE: use-after-free and memory leak
    - debian/patches/CVE-2018-100080x-pre.patch: fix use-after-free and
      introduce _from_raw_x509_ptr in OpenSSL/SSL.py, OpenSSL/crypto.py.
    - debian/patches/CVE-2018-100080x.patch: fix issues in OpenSSL/SSL.py,
      OpenSSL/crypto.py, add test to OpenSSL/test/test_ssl.py.
    - debian/control: depend on python-cryptography security update to
      get access to new X509_up_ref function.
    - CVE-2018-1000807
    - CVE-2018-1000808
  * debian/patches/update_certs.patch: update expired test certs.

 -- Marc Deslauriers <email address hidden> Wed, 07 Nov 2018 13:39:49 -0500

CVE-2018-1000807 Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling tha
CVE-2018-1000808 Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulner



About   -   Send Feedback to @ubuntu_updates