VYPR

rpm package

suse/python-ecdsa&distro=SUSE Linux Enterprise Module for Basesystem 15 SP2

pkg:rpm/suse/python-ecdsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2

Vulnerabilities (4)

  • CVE-2020-14343Feb 9, 2021
    affected < 0.13.3-3.7.1fixed 0.13.3-3.7.1

    A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrust

  • CVE-2020-25659Jan 11, 2021
    affected < 0.13.3-3.7.1fixed 0.13.3-3.7.1

    python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

  • CVE-2019-14859Jan 2, 2020
    affected < 0.13.3-3.3.1fixed 0.13.3-3.3.1

    A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could

  • CVE-2019-14853Nov 26, 2019
    affected < 0.13.3-3.3.1fixed 0.13.3-3.3.1

    An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.