EulerOS Virtualization 2.10.0 : python-cryptography (EulerOS-SA-2024-1990)
Discription

According to the versions of the python-cryptography package installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities : python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.(CVE-2020-25659) Tenable has extracted the preceding description block directly from the EulerOS Virtualization python-cryptography security advisory. Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version…Read More

Back to Main

Subscribe for the latest news: