Bug 960680 (CVE-2016-1494) - VUL-0: CVE-2016-1494: python-rsa: Possible signature forgery via Bleichenbacher attack
Summary: VUL-0: CVE-2016-1494: python-rsa: Possible signature forgery via Bleichenbach...
Status: RESOLVED FIXED
Alias: CVE-2016-1494
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/160344/
Whiteboard: CVSSv2:RedHat:CVE-2016-1494:4.3:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-05 09:22 UTC by Johannes Segitz
Modified: 2016-04-27 18:23 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2016-01-05 09:22:37 UTC
CVE-2016-1494

python-rsa is vulnerable to a Bleichenbacher attack. Details are available at
https://blog.filippo.io/bleichenbacher-06-signature-forgery-in-python-rsa/

Keys generated with python-rsa are not vulnerable by default

Proposed patch:
https://bitbucket.org/sybren/python-rsa/pull-requests/14/security-fix-bb06-attack-in-verify-by/diff

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1494
http://seclists.org/oss-sec/2016/q1/18
Comment 1 SMASH SMASH 2016-01-05 12:47:21 UTC
An update workflow for this issue was started.

This issue was rated as "moderate".
Please submit fixed packages until "Jan. 19, 2016".

When done, reassign the bug to "security-team@suse.de".
/update/121226/.
Comment 4 Robert Schweikert 2016-01-05 19:00:44 UTC
created request id 87584
Comment 6 Andreas Stieger 2016-01-07 13:10:33 UTC
Please submit for openSUSE:
openSUSE:13.1:Update/python-rsa
openSUSE:13.2:Update/python-rsa
openSUSE:Leap:42.1:Update/python-rsa
Comment 7 Robert Schweikert 2016-01-07 23:17:20 UTC
openSUSE:13.1 -> created request id 352511
openSUSE:13.2 -> created request id 352512
openSUSE:Leap:42.1 -> created request id 352513
Comment 8 Bernhard Wiedemann 2016-01-08 00:00:19 UTC
This is an autogenerated message for OBS integration:
This bug (960680) was mentioned in
https://build.opensuse.org/request/show/352511 13.1 / python-rsa
https://build.opensuse.org/request/show/352512 13.2 / python-rsa
https://build.opensuse.org/request/show/352513 42.1 / python-rsa
Comment 9 Andreas Stieger 2016-01-08 07:31:26 UTC
Thanks, updates are running.
Comment 10 Andreas Stieger 2016-01-13 14:12:50 UTC
Releasing Cloud 5 update, closing
Comment 11 Swamp Workflow Management 2016-01-13 17:14:57 UTC
SUSE-SU-2016:0107-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 960680
CVE References: CVE-2016-1494
Sources used:
SUSE Linux Enterprise Module for Public Cloud 12 (src):    python-rsa-3.1.4-11.1
Comment 12 Swamp Workflow Management 2016-01-13 18:12:00 UTC
openSUSE-SU-2016:0108-1: An update that solves one vulnerability and has two fixes is now available.

Category: security (moderate)
Bug References: 935595,954690,960680
CVE References: CVE-2016-1494
Sources used:
openSUSE Leap 42.1 (src):    python-rsa-3.1.4-5.1
openSUSE 13.2 (src):    python-rsa-3.1.4-2.3.1
openSUSE 13.1 (src):    python-rsa-3.1.4-5.3.1