Опубликовано: 14 июл. 2023
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5
Описание
cryptography mishandles SSH certificates
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-38325
- https://github.com/pyca/cryptography/issues/9207
- https://github.com/pyca/cryptography/pull/7960
- https://github.com/pyca/cryptography/pull/9208
- https://github.com/pyca/cryptography/commit/1ca7adc97b76a9dfbd3d850628b613eb93b78fc3
- https://github.com/pyca/cryptography/compare/41.0.1...41.0.2
- https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2023-112.yaml
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMCCTYY3CSNQBFFYYC5DAV6KATHWCUZK
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NMCCTYY3CSNQBFFYYC5DAV6KATHWCUZK
- https://pypi.org/project/cryptography/#history
- https://security.netapp.com/advisory/ntap-20230824-0010
Пакеты
Наименование
cryptography
pip
Затронутые версииВерсия исправления
>= 40.0.0, < 41.0.2
41.0.2
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 2 лет назад
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVSS3: 7.5
redhat
около 2 лет назад
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVSS3: 7.5
nvd
около 2 лет назад
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVSS3: 7.5
debian
около 2 лет назад
The cryptography package before 41.0.2 for Python mishandles SSH certi ...