[ubuntu/zesty-security] pyjwt 1.4.2-1ubuntu0.1 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Wed Aug 30 17:17:01 UTC 2017


pyjwt (1.4.2-1ubuntu0.1) zesty-security; urgency=medium

  * SECURITY UPDATE: symmetric/asymmetric key confusion attacks
    - debian/patches/CVE-2017-11424.patch: Throw if key is an PKCS1
      PEM-encoded public key in jwt/algorithms.py,
      tests/keys/testkey_pkcs1.pub.pem, tests/test_algorithms.py.
    - CVE-2017-11424

Date: 2017-08-29 17:05:15.654689+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/pyjwt/1.4.2-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Zesty-changes mailing list