[Freeipa] [Bug 1717356] Re: CVE-2016-6298

2018-03-07 Thread Timo Aaltonen
** Also affects: python-jwcrypto (Ubuntu Xenial) Importance: Undecided Status: New ** Changed in: python-jwcrypto (Ubuntu Xenial) Assignee: (unassigned) => Brian Morton (rokclimb15) ** Changed in: python-jwcrypto (Ubuntu) Status: In Progress => Fix Released ** Changed in: p

[Freeipa] [Bug 1717356] Re: CVE-2016-6298

2018-03-06 Thread Simon Quigley
Bump. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to python-jwcrypto in Ubuntu. https://bugs.launchpad.net/bugs/1717356 Title: CVE-2016-6298 Status in python-jwcrypto package in Ubuntu: In Progress Bug description: The _Rsa15 class in th

[Freeipa] [Bug 1717356] Re: CVE-2016-6298

2017-09-15 Thread Brian Morton
Tests are here: https://github.com/latchset/jwcrypto/pull/66/commits/b2b66b53bc0df72eb761959fe39700451803d8ab -- You received this bug notification because you are a member of FreeIPA, which is subscribed to python-jwcrypto in Ubuntu. https://bugs.launchpad.net/bugs/1717356 Title: CVE-2016-629

[Freeipa] [Bug 1717356] Re: CVE-2016-6298

2017-09-14 Thread Brian Morton
17.04 and 17.10 are not affected since they publish the fixed version 0.3.2. 16.04 appears to be affected, but the code is significantly different. I've requested info from the source project owner to test my proposed patch for 16.04. -- You received this bug notification because you are a member