Information disclosure in python-cryptography - CVE-2018-10903
Published: November 16, 2018 / Updated: November 19, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to due to insufficient enforcement of a minimum tag length prior to passing user-supplied input to the finalize_with_tag API. A remote attacker can send a specially crafted request that submits a malicious short tag length, trigger key leakage and access sensitive information.
Affected software
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Opensuse
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Red Hat OpenStack for IBM Power
Red Hat OpenStack
Red Hat OpenStack Director Deployment Tools
Red Hat OpenStack Director Deployment Tools for IBM Power
python2-cryptography-vectors
python3-cryptography-vectors
python-cryptography-debuginfo
python-cryptography-debugsource
python3-cryptography
python3-cryptography-debuginfo
python2-cryptography
python2-cryptography-debuginfo
PowerStore T
Dell EMC VxRail Appliance
How to mitigate CVE-2018-10903
python2-cryptography-vectors - update to 2.9.2-150200.3.3.1
python3-cryptography-vectors - update to 2.9.2-150200.3.3.1
python-cryptography-debuginfo - update to 2.9.2-150200.13.1
python-cryptography-debugsource - update to 2.9.2-150200.13.1
python3-cryptography - update to 2.9.2-150200.13.1
python3-cryptography-debuginfo - update to 2.9.2-150200.13.1
python2-cryptography - update to 2.9.2-150200.13.1
python2-cryptography-debuginfo - update to 2.9.2-150200.13.1
PowerStore T - update to 3.5.0.1-2083289
Dell EMC VxRail Appliance - update to 7.0.411
External References
Related Security Bulletins
- Information disclosure in python-cryptography
- Red Hat update for python-cryptography
- OpenSUSE Linux update for python-cryptography
- SUSE update for python-cryptography, python-cryptography-vectors
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell PowerStore Family