Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhm9-p9w5-fwm7

Опубликовано: 10 фев. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.8
CVSS3: 9.1

Описание

PyCA Cryptography symmetrically encrypting large values can lead to integer overflow

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. When certain sequences of update() calls with large values (multiple GBs) for symetric encryption or decryption occur, it's possible for an integer overflow to happen, leading to mishandling of buffers. This is patched in version 3.3.2 and newer.

Пакеты

Наименование

cryptography

pip
Затронутые версииВерсия исправления

>= 3.1, < 3.3.2

3.3.2

EPSS

Процентиль: 79%
0.01272
Низкий

8.8 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-190
CWE-787

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 4 лет назад

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

CVSS3: 8.2
redhat
больше 4 лет назад

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

CVSS3: 9.1
nvd
больше 4 лет назад

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

CVSS3: 9.1
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 9.1
debian
больше 4 лет назад

In the cryptography package before 3.3.2 for Python, certain sequences ...

EPSS

Процентиль: 79%
0.01272
Низкий

8.8 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-190
CWE-787