Bug 29492 - python-rsa new security issue CVE-2020-25658
Summary: python-rsa new security issue CVE-2020-25658
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-09-26 18:44 CEST by David Walser
Modified: 2021-10-02 20:59 CEST (History)
5 users (show)

See Also:
Source RPM: python-rsa-4.6-3.mga9.src.rpm
CVE: CVE-2020-25658
Status comment:


Attachments

Description David Walser 2021-09-26 18:44:16 CEST
Fedora has issued an advisory on September 24:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2SAF67KDGSOHLVFTRDOHNEAFDRSSYIWA/

The issue is fixed upstream in 4.7.2.

Mageia 8 is also affected.
David Walser 2021-09-26 18:44:39 CEST

Status comment: (none) => Fixed upstream in 4.7.2
CC: (none) => nicolas.salguero
Whiteboard: (none) => MGA8TOO

Comment 1 Nicolas Salguero 2021-09-27 11:14:40 CEST
Suggested advisory:
========================

The updated package fixes a security vulnerability:

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. (CVE-2020-25658)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25658
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/2SAF67KDGSOHLVFTRDOHNEAFDRSSYIWA/
========================

Updated package in core/updates_testing:
========================
python3-rsa-4.7.2-1.mga8

from SRPM:
python-rsa-4.7.2-1.mga8.src.rpm

Status comment: Fixed upstream in 4.7.2 => (none)
Assignee: python => qa-bugs
Whiteboard: MGA8TOO => (none)
Status: NEW => ASSIGNED
Version: Cauldron => 8
CVE: (none) => CVE-2020-25658

Comment 2 Herman Viaene 2021-09-28 15:37:33 CEST
MGA8-64 Plasma on Lenovo B 50
No installation issues.
OK'ing on clean install as we do with other developer tools.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 3 Thomas Andrews 2021-10-02 05:39:29 CEST
Validating. Advisory in Comment 1.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Dave Hodgins 2021-10-02 19:37:32 CEST

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 4 Mageia Robot 2021-10-02 20:59:03 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0456.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.