CVE-2017-1000246 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000246): Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.
@Maintainers please call for stabilization when ready. Thank you
I'm not sure we are going to be able to clean this up any time soon, but we should at least be able to stabilize it. https://github.com/openstack/requirements/blob/stable/pike/global-requirements.txt#L223
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=818d4cea619a2616e8ea576787c52b19a51884e1 commit 818d4cea619a2616e8ea576787c52b19a51884e1 Author: Matthew Thode <prometheanfire@gentoo.org> AuthorDate: 2019-04-14 07:06:42 +0000 Commit: Matthew Thode <prometheanfire@gentoo.org> CommitDate: 2019-04-14 07:06:57 +0000 dev-python/pysaml2: cleanup for CVE Bug: https://bugs.gentoo.org/639774 Package-Manager: Portage-2.3.62, Repoman-2.3.12 Signed-off-by: Matthew Thode <prometheanfire@gentoo.org> dev-python/pysaml2/Manifest | 1 - dev-python/pysaml2/pysaml2-4.0.2-r3.ebuild | 39 ------------------------------ 2 files changed, 40 deletions(-)
cleaned up