🛡️ SUSE-SU-2023:2783-1 — azure-cli-core (CVE-2022-1941 +6 more)
Description
Security update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets
This update for grpc, protobuf, python-Deprecated, python-PyGithub, python-aiocontextvars, python-avro, python-bcrypt, python-cryptography, python-cryptography-vectors, python-google-api-core, python-googleapis-common-protos, python-grpcio-gcp, python-humanfriendly, python-jsondiff, python-knack, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-psutil, python-pytest-asyncio, python-requests, python-websocket-client, python-websockets fixes the following issues:
grpc:
- Update in SLE-15 (bsc#1197726, bsc#1144068)
protobuf:
- Fix a potential DoS issue in protobuf-cpp and protobuf-python, CVE-2022-1941, bsc#1203681
- Fix a potential DoS issue when parsing with binary data in protobuf-java, CVE-2022-3171, bsc#1204256
- Fix potential Denial of Service in protobuf-java in the parsing procedure for binary data, CVE-2021-22569, bsc#1194530
- Add missing dependency of python subpackages on python-six (bsc#1177127)
- Updated to version 3.9.2 (bsc#1162343)
- Remove OSReadLittle* due to alignment requirements.
- Don't use unions and instead use memcpy for the type swaps.
- Disable LTO (bsc#1133277)
python-aiocontextvars:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
python-avro:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
python-cryptography:
- update to 3.3.2 (bsc#1182066, CVE-2020-36242, bsc#1198331)
- SECURITY ISSUE: Fixed a bug where certain sequences of update()
calls when symmetrically encrypting very large payloads (>2GB) could
result in an integer overflow, leading to buffer overflows.
CVE-2020-36242
python-cryptography-vectors:
- update to 3.2 (bsc#1178168, CVE-2020-25659):
- CVE-2020-25659: Attempted to make RSA PKCS#1v1.5 decryption more constant time,
to protect against Bleichenbacher vulnerabilities. Due to limitations imposed
by our API, we cannot completely mitigate this vulnerability.
- Support for OpenSSL 1.0.2 has been removed.
- Added basic support for PKCS7 signing (including SMIME) via PKCS7SignatureBuilder.
- update to 3.3.2 (bsc#1198331)
python-Deprecated:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- update to 1.2.13:
python-google-api-core:
- Update to 1.14.2
python-googleapis-common-protos:
- Update to 1.6.0
python-grpcio-gcp:
- Initial spec for v0.2.2
python-humanfriendly:
- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Update to 10.0
python-jsondiff:
- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Update to version 1.3.0
python-knack:
- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Update to version 0.9.0
python-opencensus:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Disable Python2 build
- Update to 0.8.0
python-opencensus-context:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
python-opencensus-ext-threading:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Initial build version 0.1.2
python-opentelemetry-api:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Version update to 1.5.0
python-psutil:
- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- update to 5.9.1
- remove the dependency on net-tools, since it conflicts with busybox-hostnmame which is default on MicroOS. (bsc#1184753)
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
python-PyGithub:
- Update to 1.43.5:
python-pytest-asyncio:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Initial release of python-pytest-asyncio 0.8.0
python-requests:
- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
python-websocket-client:
- Update in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- Update to version 1.3.2
python-websockets:
- Include in SLE-15 (bsc#1199282, jsc#PM-3243, jsc#SLE-24629)
- update to 9.1:
Affected software
SUSE-SU-2023:2783-1 is recorded against 31 packages.
- azure-cli-core (fixed in 2.17.1-150100.6.18.1)
- grpc (fixed in 1.25.0-150100.3.3.3)
- protobuf (fixed in 3.9.2-150100.8.3.3)
- python-aiocontextvars (fixed in 0.2.2-150100.3.3.3)
- python-automat (fixed in 0.6.0-150000.3.4.1)
- python-avro (fixed in 1.11.0-150100.3.3.3)
- python-constantly (fixed in 15.1.0-150000.3.4.1)
- python-cryptography (fixed in 3.3.2-150100.7.15.3)
- python-cryptography-vectors (fixed in 3.3.2-150100.3.11.3)
- python-deprecated (fixed in 1.2.13-150100.3.3.3)
- python-google-api-core (fixed in 1.14.2-150100.3.3.3)
- python-googleapis-common-protos (fixed in 1.6.0-150100.3.3.3)
- python-grpcio-gcp (fixed in 0.2.2-150100.3.3.3)
- python-humanfriendly (fixed in 10.0-150100.6.3.3)
- python-hyperlink (fixed in 17.2.1-150000.3.4.1)
- python-incremental (fixed in 17.5.0-150000.3.4.1)
- python-jsondiff (fixed in 1.3.0-150100.3.6.3)
- python-knack (fixed in 0.9.0-150100.3.7.3)
- python-opencensus (fixed in 0.8.0-150100.3.3.3)
- python-opencensus-context (fixed in 0.1.2-150100.3.3.3)
- python-opencensus-ext-threading (fixed in 0.1.2-150100.3.3.3)
- python-opentelemetry-api (fixed in 1.5.0-150100.3.3.3)
- python-psutil (fixed in 5.9.1-150100.6.6.3)
- python-pygithub (fixed in 1.43.5-150100.3.3.3)
Show the remaining 7 packages
- python-pytest (fixed in 3.10.1-150000.7.5.1)
- python-pytest-asyncio (fixed in 0.8.0-150100.3.3.3)
- python-requests (fixed in 2.25.1-150100.6.13.3)
- python-twisted (fixed in 17.9.0-150000.3.8.1)
- python-websocket-client (fixed in 1.3.2-150100.6.7.3)
- python-websockets (fixed in 9.1-150100.3.3.3)
- python-zope.interface (fixed in 4.4.2-150000.3.4.1)
Timeline and source
Published on 4 July 2023 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| azure-cli-core | — | 2.17.1-150100.6.18.1 |
| grpc | — | 1.25.0-150100.3.3.3 |
| protobuf | — | 3.9.2-150100.8.3.3 |
| python-aiocontextvars | — | 0.2.2-150100.3.3.3 |
| python-automat | — | 0.6.0-150000.3.4.1 |
| python-avro | — | 1.11.0-150100.3.3.3 |
| python-constantly | — | 15.1.0-150000.3.4.1 |
| python-cryptography | — | 3.3.2-150100.7.15.3 |
| python-cryptography-vectors | — | 3.3.2-150100.3.11.3 |
| python-deprecated | — | 1.2.13-150100.3.3.3 |
| python-google-api-core | — | 1.14.2-150100.3.3.3 |
| python-googleapis-common-protos | — | 1.6.0-150100.3.3.3 |
| python-grpcio-gcp | — | 0.2.2-150100.3.3.3 |
| python-humanfriendly | — | 10.0-150100.6.3.3 |
| python-hyperlink | — | 17.2.1-150000.3.4.1 |
| python-incremental | — | 17.5.0-150000.3.4.1 |
| python-jsondiff | — | 1.3.0-150100.3.6.3 |
| python-knack | — | 0.9.0-150100.3.7.3 |
| python-opencensus | — | 0.8.0-150100.3.3.3 |
| python-opencensus-context | — | 0.1.2-150100.3.3.3 |
| python-opencensus-ext-threading | — | 0.1.2-150100.3.3.3 |
| python-opentelemetry-api | — | 1.5.0-150100.3.3.3 |
| python-psutil | — | 5.9.1-150100.6.6.3 |
| python-pygithub | — | 1.43.5-150100.3.3.3 |
| python-pytest | — | 3.10.1-150000.7.5.1 |
| python-pytest-asyncio | — | 0.8.0-150100.3.3.3 |
| python-requests | — | 2.25.1-150100.6.13.3 |
| python-twisted | — | 17.9.0-150000.3.8.1 |
| python-websocket-client | — | 1.3.2-150100.6.7.3 |
| python-websockets | — | 9.1-150100.3.3.3 |
| python-zope.interface | — | 4.4.2-150000.3.4.1 |
References
Similar Threats
- Unknown SUSE-RU-2026:2237-1
- Unknown openSUSE-SU-2026:10211-1
- Unknown SUSE-SU-2026:0273-1
- Unknown SUSE-SU-2025:1182-1
- Unknown SUSE-SU-2025:1019-1
Free Vulnerability Check
Is your site affected by SUSE-SU-2023:2783-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2023:2783-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.