Bug 23822

Summary: python-OpenSSL new security issues CVE-2018-100080[78]
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Python Stack Maintainers <python>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: major    
Priority: Normal CC: makowski.mageia, marja11, mhrambo3501
Version: 6   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: python-OpenSSL-16.1.0-1.mga6.src.rpm CVE:
Status comment:

Description David Walser 2018-11-08 18:25:57 CET
Ubuntu has issued an advisory today (November 8):
https://usn.ubuntu.com/3813-1/

The issues are fixed upstream in 17.5.0 (already in Cauldron).
Comment 1 Marja Van Waes 2018-11-08 23:00:43 CET
Assigning to the Python maintainers, CC'ing the registered maintainer.

CC: (none) => makowski.mageia, marja11
Assignee: bugsquad => python

Comment 2 David Walser 2019-01-17 15:47:15 CET
RedHat has issued an advisory for this on January 16:
https://access.redhat.com/errata/RHSA-2019:0085
Comment 3 David Walser 2019-05-03 18:32:13 CEST
openSUSE has issued an advisory for this on April 2:
https://lists.opensuse.org/opensuse-updates/2019-04/msg00032.html

python-cryptography may need a patch to support the fix.
Comment 4 Mike Rambo 2019-11-06 13:45:45 CET
Mageia 6 is EOL.

CC: (none) => mrambo
Resolution: (none) => OLD
Status: NEW => RESOLVED