Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the OpenSSL backend of python-cryptography: The OpenSSL backend prior to 1.0.2 made extensive use of assertions to check response codes where our tests could not trigger a failure. However, when Python is run with -O these asserts are optimized away. If a user ran Python with this flag and got an invalid response code this could result in undefined behavior or worse. Accordingly, all response checks from the OpenSSL backend have been converted from assert to a true function call. This issue has been fixed in the 1.0.2 version of python-cryptography. Upstream changelog: https://cryptography.io/en/stable/changelog/#id1 Related commits: https://github.com/pyca/cryptography/commit/e3675af0f42e1f3117b61984805c192c1937a64f https://github.com/pyca/cryptography/commit/3c39eba249bfd4582cfb4f169d7c47492b5369e3 https://github.com/pyca/cryptography/commit/7712edc5fa2bc5244221c35cf97e1b58f5981446 https://github.com/pyca/cryptography/commit/2917e460993c475c72d7146c50dc3bbc2414280d https://github.com/pyca/cryptography/commit/915e0a1194400203b0e49e05de5facbc4ac8eb66 https://github.com/pyca/cryptography/commit/5fed07c15c696d8c82ef04b4a0e8435b444f4f17
Created python-cryptography tracking bugs for this issue: Affects: fedora-all [bug 1267554] Affects: epel-7 [bug 1267556]
python-cryptography-1.0.2-2.fc23, python-cryptography-vectors-1.0.2-2.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
*** Bug 1288254 has been marked as a duplicate of this bug. ***