UbuntuUpdates.org

Package "python3-cryptography"

Name: python3-cryptography

Description:

Python library exposing cryptographic recipes and primitives (Python 3)

Latest version: 2.1.4-1ubuntu1.4
Release: bionic (18.04)
Level: security
Repository: main
Head package: python-cryptography
Homepage: https://cryptography.io/

Links


Download "python3-cryptography"


Other versions of "python3-cryptography" in Bionic

Repository Area Version
base main 2.1.4-1ubuntu1.1
updates main 2.1.4-1ubuntu1.4

Changelog

Version: 2.1.4-1ubuntu1.4 2020-11-03 15:07:13 UTC

  python-cryptography (2.1.4-1ubuntu1.4) bionic-security; urgency=medium

  * SECURITY UPDATE: Bleichenbacher timing oracle attack
    - debian/patches/CVE-2020-25659.patch: Attempt to mitigate
      Bleichenbacher attacks on RSA decryption docs/spelling_wordlist.txt,
      src/cryptography/hazmat/backends/openssl/rsa.py.
    - CVE-2020-25659

 -- <email address hidden> (Leonidas S. Barbosa) Wed, 28 Oct 2020 13:50:26 -0300

Source diff to previous version
CVE-2020-25659 bleichenbacher timing oracle attack against RSA decryption

Version: 2.1.4-1ubuntu1.3 2019-08-20 13:07:09 UTC

  python-cryptography (2.1.4-1ubuntu1.3) bionic; urgency=medium

  * Rebuild against OpenSSL 1.1.1, cherrypick upstream testsuite fix for
    1.1.1. LP: #1797386

 -- Dimitri John Ledkov <email address hidden> Mon, 17 Dec 2018 11:16:35 +1100

Source diff to previous version

Version: 2.1.4-1ubuntu1.2 2018-07-23 19:06:39 UTC

  python-cryptography (2.1.4-1ubuntu1.2) bionic-security; urgency=medium

  * SECURITY UPDATE: GCM disallow implicit tag truncation
    - debian/patches/CVE-2018-10903.patch: fix in
      docs/hazmat/primitives/symmetric-encryption.rst,
      src/cryptography/hazmat/backends/openssl/ciphers.py,
      src/cryptography/hazmat/primitives/ciphers/modes.py,
      tests/hazmat/primitives/test_aes.py.
    - CVE-2018-10903

 -- <email address hidden> (Leonidas S. Barbosa) Fri, 20 Jul 2018 11:09:59 -0300

CVE-2018-10903 GCM tag forgery via truncated tag in finalize_with_tag API



About   -   Send Feedback to @ubuntu_updates