Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-7096

Опубликовано: 17 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-7096: python-cryptography security update (MODERATE)

[3.2.1-6]

  • Fix CVE-2023-23931: Don't allow update_into to mutate immutable objects, resolves rhbz#2172404

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

python3-cryptography

3.2.1-6.el8

Oracle Linux x86_64

python3-cryptography

3.2.1-6.el8

Связанные CVE

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 6.5
redhat
больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 4.8
nvd
больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 6.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 4.8
debian
больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives ...