QID 981118
QID 981118: Python (pip) Security Update for tlslite-ng (GHSA-cwh5-3cw7-4286)
tlslite-ng version 0.7.3 and earlier, since commit d7b288316bca7bcdd082e6ccff5491e241305233 contains a CWE-354: Improper Validation of Integrity Check Value vulnerability in TLS implementation, tlslite/utils/constanttime.py: ct_check_cbc_mac_and_pad(); line "end_pos = data_len - 1 - mac.digest_size" that can result in an attacker manipulating the TLS ciphertext which will not be detected by receiving tlslite-ng. This attack appears to be exploitable via man in the middle on a network connection. This vulnerability appears to have been fixed after commit 3674815d1b0f7484454995e2737a352e0a6a93d8.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cwh5-3cw7-4286 for updates pertaining to this vulnerability.
Vendor References
- GHSA-cwh5-3cw7-4286 -
github.com/advisories/GHSA-cwh5-3cw7-4286
CVEs related to QID 981118
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cwh5-3cw7-4286 | tlslite-ng |
|