Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 792564 (CVE-2021-33880) - <dev-python/websockets-9.1: timing attacks on HTTP Basic Auth passwords (CVE-2021-33880)
Summary: <dev-python/websockets-9.1: timing attacks on HTTP Basic Auth passwords (CVE-...
Status: RESOLVED FIXED
Alias: CVE-2021-33880
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-05-27 22:50 UTC by Michał Górny
Modified: 2021-06-09 04:27 UTC (History)
2 users (show)

See Also:
Package list:
dev-python/websockets-9.1
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2021-05-27 22:50:49 UTC
+*May 27, 2021*
+
+.. note::
+
+    **Version 9.1 fixes a security issue introduced in version 8.0.**
+
+    Version 8.0 was vulnerable to timing attacks on HTTP Basic Auth passwords.
Comment 1 NATTkA bot gentoo-dev 2021-05-27 22:52:18 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-05-27 23:20:23 UTC
All sanity-check issues have been resolved
Comment 3 Agostino Sarubbo gentoo-dev 2021-05-28 07:35:34 UTC
x86 stable
Comment 4 Agostino Sarubbo gentoo-dev 2021-05-29 08:41:24 UTC
amd64 stable
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-30 05:15:04 UTC
arm done

all arches done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-05-30 05:40:57 UTC
Please cleanup, thanks!
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-06-09 04:27:49 UTC
Cleanup done and noglsa so all done!

commit 23402fd4f2821904847244bda4a4ce14a3e7b955
Author: Michał Górny <mgorny@gentoo.org>
Date:   Sun May 30 11:40:39 2021 +0200

    dev-python/websockets: Remove old

    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 delete mode 100644 dev-python/websockets/websockets-8.1.ebuild
 delete mode 100644 dev-python/websockets/websockets-9.0.1.ebuild
 delete mode 100644 dev-python/websockets/websockets-9.0.2.ebuild
 delete mode 100644 dev-python/websockets/websockets-9.0.ebuild