Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-6615

Опубликовано: 11 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-6615: python-cryptography security update (MODERATE)

[36.0.1-4]

  • Fix FTBFS caused by rsa_pkcs1_implicit_rejection OpenSSL feature, resolves rhbz#2203840

[36.0.1-3]

  • Fix CVE-2023-23931: Don't allow update_into to mutate immutable objects, resolves rhbz#2172399
  • Fix FTBFS due to failing test_load_invalid_ec_key_from_pem and test_decrypt_invalid_decrypt

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

python3-cryptography

36.0.1-4.el9

Oracle Linux x86_64

python3-cryptography

36.0.1-4.el9

Связанные CVE

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 6.5
redhat
больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 4.8
nvd
больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 6.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 4.8
debian
больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives ...