[ubuntu/zesty-security] pyjwt 1.4.2-1ubuntu0.1 (Accepted)
Leonidas S. Barbosa
leo.barbosa at canonical.com
Wed Aug 30 17:17:01 UTC 2017
pyjwt (1.4.2-1ubuntu0.1) zesty-security; urgency=medium
* SECURITY UPDATE: symmetric/asymmetric key confusion attacks
- debian/patches/CVE-2017-11424.patch: Throw if key is an PKCS1
PEM-encoded public key in jwt/algorithms.py,
tests/keys/testkey_pkcs1.pub.pem, tests/test_algorithms.py.
- CVE-2017-11424
Date: 2017-08-29 17:05:15.654689+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/pyjwt/1.4.2-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Zesty-changes
mailing list