<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for python-pyOpenSSL</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2024:1626-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-05-13T14:27:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-05-13T14:27:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-05-13T14:27:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for python-pyOpenSSL</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for python-pyOpenSSL fixes the following issues:

- CVE-2018-1000807: Fixed a use-after-free in X509 object handling (bsc#1111635)
- CVE-2018-1000808: Fixed a use-after-free in PKCS #12 Store (bsc#1111634)
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Image SLES12-SP5-Azure-BYOS-2024-1626,Image SLES12-SP5-Azure-Basic-On-Demand-2024-1626,Image SLES12-SP5-Azure-HPC-BYOS-2024-1626,Image SLES12-SP5-Azure-HPC-On-Demand-2024-1626,Image SLES12-SP5-Azure-SAP-BYOS-2024-1626,Image SLES12-SP5-Azure-SAP-On-Demand-2024-1626,Image SLES12-SP5-Azure-Standard-On-Demand-2024-1626,Image SLES12-SP5-EC2-BYOS-2024-1626,Image SLES12-SP5-EC2-ECS-On-Demand-2024-1626,Image SLES12-SP5-EC2-On-Demand-2024-1626,Image SLES12-SP5-EC2-SAP-BYOS-2024-1626,Image SLES12-SP5-EC2-SAP-On-Demand-2024-1626,Image SLES12-SP5-GCE-BYOS-2024-1626,Image SLES12-SP5-GCE-On-Demand-2024-1626,Image SLES12-SP5-GCE-SAP-BYOS-2024-1626,Image SLES12-SP5-GCE-SAP-On-Demand-2024-1626,Image SLES12-SP5-SAP-Azure-LI-BYOS-Production-2024-1626,Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production-2024-1626,SUSE-2024-1626,SUSE-SLE-SERVER-12-SP5-2024-1626</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20241626-1/</URL>
      <Description>Link for SUSE-SU-2024:1626-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2024-May/035247.html</URL>
      <Description>E-Mail link for SUSE-SU-2024:1626-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1021578</URL>
      <Description>SUSE Bug 1021578</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1111634</URL>
      <Description>SUSE Bug 1111634</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1111635</URL>
      <Description>SUSE Bug 1111635</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-1000807/</URL>
      <Description>SUSE CVE CVE-2018-1000807 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-1000808/</URL>
      <Description>SUSE CVE CVE-2018-1000808 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-BYOS">Image SLES12-SP5-Azure-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-Basic-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-Basic-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-Basic-On-Demand">Image SLES12-SP5-Azure-Basic-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-HPC-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-HPC-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-BYOS">Image SLES12-SP5-Azure-HPC-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-HPC-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-HPC-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-On-Demand">Image SLES12-SP5-Azure-HPC-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-BYOS">Image SLES12-SP5-Azure-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-On-Demand">Image SLES12-SP5-Azure-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-Azure-Standard-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-Azure-Standard-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-Azure-Standard-On-Demand">Image SLES12-SP5-Azure-Standard-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-EC2-BYOS">Image SLES12-SP5-EC2-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-ECS-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-ECS-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand">Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-On-Demand">Image SLES12-SP5-EC2-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-BYOS">Image SLES12-SP5-EC2-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-EC2-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-EC2-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-On-Demand">Image SLES12-SP5-EC2-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-GCE-BYOS">Image SLES12-SP5-GCE-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-GCE-On-Demand">Image SLES12-SP5-GCE-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-SAP-BYOS">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-SAP-BYOS">
        <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-BYOS">Image SLES12-SP5-GCE-SAP-BYOS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-GCE-SAP-On-Demand">
      <Branch Type="Product Name" Name="Image SLES12-SP5-GCE-SAP-On-Demand">
        <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-On-Demand">Image SLES12-SP5-GCE-SAP-On-Demand</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <Branch Type="Product Name" Name="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
        <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5" CPE="cpe:/o:suse:sles:12:sp5">SUSE Linux Enterprise Server 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5" CPE="cpe:/o:suse:sles_sap:12:sp5">SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="python-pyOpenSSL-17.1.0-4.26.1">
      <FullProductName ProductID="python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-pyOpenSSL-17.1.0-4.26.1">
      <FullProductName ProductID="python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-pyOpenSSL-doc-17.1.0-4.26.1">
      <FullProductName ProductID="python-pyOpenSSL-doc-17.1.0-4.26.1">python-pyOpenSSL-doc-17.1.0-4.26.1</FullProductName>
    </Branch>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-BYOS:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-BYOS:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-Basic-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-Basic-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-Basic-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-HPC-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-BYOS:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-HPC-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-HPC-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-BYOS:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-HPC-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-HPC-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-HPC-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-HPC-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-Azure-Standard-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-Azure-Standard-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-Azure-Standard-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-BYOS:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-BYOS:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-ECS-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-ECS-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-ECS-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-ECS-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-On-Demand:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-EC2-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-EC2-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-EC2-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-BYOS:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-BYOS:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-GCE-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-GCE-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-GCE-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-GCE-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-BYOS">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-GCE-SAP-BYOS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-GCE-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-GCE-SAP-On-Demand">
      <FullProductName ProductID="Image SLES12-SP5-GCE-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-GCE-SAP-On-Demand</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-SAP-Azure-LI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production">
      <FullProductName ProductID="Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP5:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of SUSE Linux Enterprise Server 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:python-pyOpenSSL-17.1.0-4.26.1">python-pyOpenSSL-17.1.0-4.26.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-pyOpenSSL-17.1.0-4.26.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP5:python3-pyOpenSSL-17.1.0-4.26.1">python3-pyOpenSSL-17.1.0-4.26.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP5</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a reference to the memory.. This vulnerability appears to have been fixed in 17.5.0.</Note>
    </Notes>
    <CVE>CVE-2018-1000807</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-Azure-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Basic-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Standard-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20241626-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-1000807.html</URL>
        <Description>CVE-2018-1000807</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1111634</URL>
        <Description>SUSE Bug 1111634</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1111635</URL>
        <Description>SUSE Bug 1111635</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploitable via Depends upon calling application, however it could be as simple as initiating a TLS connection. Anything that would cause the calling application to reload certificates from a PKCS #12 store.. This vulnerability appears to have been fixed in 17.5.0.</Note>
    </Notes>
    <CVE>CVE-2018-1000808</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Image SLES12-SP5-Azure-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Basic-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-HPC-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-Azure-Standard-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-ECS-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-EC2-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-BYOS:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-GCE-SAP-On-Demand:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-LI-BYOS-Production:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP5:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:python-pyOpenSSL-17.1.0-4.26.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP5:python3-pyOpenSSL-17.1.0-4.26.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20241626-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-1000808.html</URL>
        <Description>CVE-2018-1000808</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1111634</URL>
        <Description>SUSE Bug 1111634</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1111635</URL>
        <Description>SUSE Bug 1111635</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
