tallship on Nostr: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] python3 ...
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
[slackware-security] python3 (SSA:2023-258-01)
New python3 packages are available for Slackware 15.0 and -current to
fix a security issue.
Here are the details from the Slackware 15.0 ChangeLog:
+--------------------------+
patches/packages/python3-3.9.18-i586-1_slack15.0.txz: Upgraded.
This update fixes a security issue:
Fixed an issue where instances of ssl.SSLSocket were vulnerable to a bypass
of the TLS handshake and included protections (like certificate verification)
and treating sent unencrypted data as if it were post-handshake TLS encrypted
data. Security issue reported by Aapo Oksman; patch by Gregory P. Smith.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2023-40217(* Security fix *)
+--------------------------+
Published at
2023-09-16 07:24:32Event JSON
{
"id": "4362e6ed77112353303fcfdf396af88517b32f3aeff2a43637536d98a06bd657",
"pubkey": "97d43c436077d94c6ce332002d7800103ef4f05dece192d2c27eb953dffb948a",
"created_at": 1694849072,
"kind": 1,
"tags": [
[
"proxy",
"https://public.mitra.social/objects/018a9ce0-7d80-9d1a-ee50-c05c407599d0",
"activitypub"
]
],
"content": "-----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA1\n\n[slackware-security] python3 (SSA:2023-258-01)\n\nNew python3 packages are available for Slackware 15.0 and -current to\nfix a security issue.\n\nHere are the details from the Slackware 15.0 ChangeLog:\n+--------------------------+\npatches/packages/python3-3.9.18-i586-1_slack15.0.txz: Upgraded.\nThis update fixes a security issue:\nFixed an issue where instances of ssl.SSLSocket were vulnerable to a bypass\nof the TLS handshake and included protections (like certificate verification)\nand treating sent unencrypted data as if it were post-handshake TLS encrypted\ndata. Security issue reported by Aapo Oksman; patch by Gregory P. Smith.\nFor more information, see:\nhttps://www.cve.org/CVERecord?id=CVE-2023-40217\n(* Security fix *)\n+--------------------------+",
"sig": "37a8327a36d09488f7652f75d055866654d457f376af4e72e1bc3ea044cd7e06a07ed5aaf8e75da4b7a8278fae59f086dd6b93c66a06f6411b0314a184f089c3"
}