[Freeipa] [Bug 1717356] Re: CVE-2016-6298

2017-09-15 Thread Brian Morton
Tests are here: https://github.com/latchset/jwcrypto/pull/66/commits/b2b66b53bc0df72eb761959fe39700451803d8ab -- You received this bug notification because you are a member of FreeIPA, which is subscribed to python-jwcrypto in Ubuntu. https://bugs.launchpad.net/bugs/1717356 Title: CVE-2016-629

[Freeipa] [Bug 1717356] Re: CVE-2016-6298

2017-09-14 Thread Brian Morton
17.04 and 17.10 are not affected since they publish the fixed version 0.3.2. 16.04 appears to be affected, but the code is significantly different. I've requested info from the source project owner to test my proposed patch for 16.04. -- You received this bug notification because you are a member

[Freeipa] [Bug 1717356] [NEW] CVE-2016-6298

2017-09-14 Thread Brian Morton
Message Attack (MMA). https://people.canonical.com/~ubuntu- security/cve/2016/CVE-2016-6298.html ** Affects: python-jwcrypto (Ubuntu) Importance: Undecided Assignee: Brian Morton (rokclimb15) Status: In Progress ** Information type changed from Private Security to Public