[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-446 --- python-cryptography

ID: oval:org.secpod.oval:def:19500520Date: (C)2024-01-04   (M)2024-02-26
Class: PATCHFamily: unix




cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling 'load_pem_pkcs7_certificates' or 'load_der_pkcs7_certificates' could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6

Platform:
Amazon Linux 2023
Product:
python-cryptography
python3-cryptography
Reference:
ALAS2023-2023-446
CVE-2023-49083
CVE    1
CVE-2023-49083
CPE    2
cpe:/a:python:python-cryptography
cpe:/a:python:python3-cryptography

© SecPod Technologies