[ubuntu/xenial-security] pyjwt 1.3.0-1ubuntu0.1 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Wed Aug 30 17:17:02 UTC 2017


pyjwt (1.3.0-1ubuntu0.1) xenial-security; urgency=medium

  * SECURITY UPDATE: symmetric/asymmetric key confusion attacks
    - debian/patches/CVE-2017-11424.patch: Throw if key is an PKCS1
      PEM-encoded public key in jwt/algorithms.py,
      tests/keys/testkey_pkcs1.pub.pem, tests/test_algorithms.py.
    - CVE-2017-11424

Date: 2017-08-29 18:37:17.524901+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/pyjwt/1.3.0-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list