Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-50782

Опубликовано: 05 фев. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-cryptographyfixed42.0.5-1package
python-cryptographyignoredbookwormpackage
python-cryptographyignoredbullseyepackage
python-cryptographyno-dsabusterpackage

Примечания

  • https://github.com/pyca/cryptography/issues/9785

  • https://people.redhat.com/~hkario/marvin/

  • https://github.com/openssl/openssl/pull/13817

  • CVE is for incomplete fix of CVE-2020-25659

  • The fix relies on OpenSSL 3.2, marking the first 42.x upload to unstable as fixed,

  • openssl 3.2 was uploaded to unstable shortly after

EPSS

Процентиль: 71%
0.00707
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
redhat
больше 1 года назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
msrc
12 месяцев назад

Описание отсутствует

suse-cvrf
8 месяцев назад

Security update for openssl-3

EPSS

Процентиль: 71%
0.00707
Низкий