From 5c5e9714c851027611cb726a76ebb8be6d48cbdc Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 2 Jul 2024 08:01:06 +0100 Subject: gentoo auto-resync : 02:07:2024 - 08:01:06 --- metadata/glsa/glsa-202407-06.xml | 49 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 metadata/glsa/glsa-202407-06.xml (limited to 'metadata/glsa/glsa-202407-06.xml') diff --git a/metadata/glsa/glsa-202407-06.xml b/metadata/glsa/glsa-202407-06.xml new file mode 100644 index 000000000000..7589ec48580e --- /dev/null +++ b/metadata/glsa/glsa-202407-06.xml @@ -0,0 +1,49 @@ + + + + cryptography: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in cryptography, the worst of which could lead to a denial of service. + cryptography + 2024-07-01 + 2024-07-01 + 769419 + 864049 + 893576 + 918685 + 925120 + remote + + + 42.0.4 + 42.0.4 + + + +

cryptography is a package which provides cryptographic recipes and primitives to Python developers.

+
+ +

Multiple vulnerabilities have been discovered in cryptography. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All cryptography users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-python/cryptography-42.0.4" + +
+ + CVE-2020-36242 + CVE-2023-23931 + CVE-2023-49083 + CVE-2024-26130 + + graaff + ajak +
\ No newline at end of file -- cgit v1.2.3