Univention Bugzilla – Bug 56079
python-ipaddress: Multiple issues (5.0)
Last modified: 2023-05-24 15:43:43 CEST
New Debian python-ipaddress 1.0.17-1+deb10u1 fixes: This update addresses the following issue: 1.0.17-1+deb10u1 (Tue, 16 May 2023 00:05:46 +0200) * Non-maintainer upload by the LTS Security Team. * CVE-2020-14422: The __hash__() methods of classes IPv4Interface and IPv6Interface had issue of generating constant hash values of 32 and 128 respectively causing hash collisions, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects. The attacker can moreover cause many dictionary entries to be created.
--- mirror/ftp/pool/main/p/python-ipaddress/python-ipaddress_1.0.17-1.dsc +++ apt/ucs_5.0-0-errata5.0-3/source/python-ipaddress_1.0.17-1+deb10u1.dsc @@ -1,3 +1,14 @@ +1.0.17-1+deb10u1 [Tue, 16 May 2023 00:05:46 +0200] Guilhem Moulin <guilhem@debian.org>: + + * Non-maintainer upload by the LTS Security Team. + * CVE-2020-14422: The __hash__() methods of classes IPv4Interface and + IPv6Interface had issue of generating constant hash values of 32 and 128 + respectively causing hash collisions, which might allow a remote attacker + to cause a denial of service if an application is affected by the + performance of a dictionary containing IPv4Interface or IPv6Interface + objects. The attacker can moreover cause many dictionary entries to be + created. + 1.0.17-1 [Mon, 31 Oct 2016 18:01:13 -0400] Barry Warsaw <barry@debian.org>: * Team upload. <http://piuparts.knut.univention.de/5.0-3/#2824205287687059399>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-3] 4e62aa1bff Bug #56079: python-ipaddress 1.0.17-1+deb10u1 doc/errata/staging/python-ipaddress.yaml | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) [5.0-3] 09878df0c6 Bug #56079: python-ipaddress 1.0.17-1+deb10u1 doc/errata/staging/python-ipaddress.yaml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x671>