Site icon API Security Blog

EulerOS Virtualization 2.10.1 : python-cryptography (EulerOS-SA-2024-2008)

According to the versions of the python-cryptography package installed, the EulerOS Virtualization installation on the remote host is affected by the following vulnerabilities : python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.(CVE-2020-25659) Tenable has extracted the preceding description block directly from the EulerOS Virtualization python-cryptography security advisory. Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version…Read More

Exit mobile version