Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-36242

Опубликовано: 09 дек. 2020
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

A buffer-overflow flaw was found in the python-cryptography package. In certain sequences of update() calls when symmetrically encrypting very large payloads (>2GB) could result in an integer overflow, leading to buffer overflows. Note: This fix is a workaround for the OpenSSL CVE-2021-23840 flaw. Source: pyca/cryptography project

Отчет

Triggering this flaw on in versions of python-cryptography as shipped with Red Hat Enterprise Linux 8 BaseOS, Appstream, as well as Red Hat Software Collections, can result in denial of service due to memory consumption or MemoryError exception. In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-cryptography package.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5python-cryptographyNot affected
Red Hat Ansible Automation Platform 1.2cryptographyWill not fix
Red Hat Ansible Automation Platform 1.2python-cryptographyWill not fix
Red Hat Ansible Engine 2python-cryptographyOut of support scope
Red Hat Ansible Tower 3cryptographyWill not fix
Red Hat Enterprise Linux 7python-cryptographyOut of support scope
Red Hat Enterprise Linux 8python38:3.8/python-cryptographyWill not fix
Red Hat Enterprise Linux 8python39:3.9/python-cryptographyWill not fix
Red Hat Enterprise Linux 9python-cryptographyNot affected
Red Hat OpenStack Platform 13 (Queens)python-cryptographyWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1926226python-cryptography: Large inputs for symmetric encryption can trigger integer overflow leading to buffer overflow

EPSS

Процентиль: 79%
0.01272
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 4 лет назад

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

CVSS3: 9.1
nvd
больше 4 лет назад

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

CVSS3: 9.1
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 9.1
debian
больше 4 лет назад

In the cryptography package before 3.3.2 for Python, certain sequences ...

suse-cvrf
больше 4 лет назад

Security update for python-cryptography

EPSS

Процентиль: 79%
0.01272
Низкий

8.2 High

CVSS3