Advisories ยป MGASA-2020-0295

Updated cloud-init packages fix security vulnerability

Publication date: 31 Jul 2020
Modification date: 31 Jul 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-8631 , CVE-2020-8632

Description

In cloud-init, relies on Mersenne Twister for a random password, which
makes it easier for attackers to predict passwords, because rand_str in
cloudinit/util.py calls the random.choice function (CVE-2020-8631).

In cloud-init, rand_user_password in cloudinit/config/cc_set_passwords.py
has a small default pwlen value, which makes it easier for attackers to
guess passwords (CVE-2020-8632).
                

References

SRPMS

7/core