Updated cloud-init packages fix security vulnerability
Publication date: 31 Jul 2020Modification date: 31 Jul 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-8631 , CVE-2020-8632
Description
In cloud-init, relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function (CVE-2020-8631). In cloud-init, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords (CVE-2020-8632).
References
SRPMS
7/core
- cloud-init-0.7.5-7.1.mga7