Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-49083

Опубликовано: 28 нояб. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling load_pem_pkcs7_certificates or load_der_pkcs7_certificates could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

A null-pointer dereference vulnerability was found in python-cryptography during the loading of PKCS7 certificates. Invoking "load_pem_pkcs7_certificates" or "load_der_pkcs7_certificates" can trigger this issue and lead to subsequent segmentation fault and result in a Denial of Service (DoS) for any application aiming to deserialize a PKCS7 blob or certificate. The potential impact includes disruptions in system availability and stability.

Отчет

This vulnerability arises when functions like "load_pem_pkcs7_certificates" or "load_der_pkcs7_certificates" are invoked, triggering the issue during the deserialization of PKCS7 blobs or certificates. The moderate rating is based on the fact that the vulnerability can lead to a segmentation fault, posing a risk of disrupting the normal functioning of any application attempting to deserialize the mentioned certificates. While the impact is significant in terms of service denial and potential system instability, the severity is deemed moderate as it does not directly expose sensitive data or allow for remote code execution, focusing primarily on the localized consequences of a DoS scenario.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2python3x-ansible-compatNot affected
Red Hat Ansible Automation Platform 2python-ansible-compatNot affected
Red Hat Ceph Storage 4ansible-runner-serviceAffected
Red Hat Certification for Red Hat Enterprise Linux 8redhat-certification-baremetal-containerAffected
Red Hat Discoverydiscovery-server-containerNot affected
Red Hat Enterprise Linux 7python-cryptographyOut of support scope
Red Hat Enterprise Linux 8python3.12-cryptographyNot affected
Red Hat Enterprise Linux 8python39:3.9/python-cryptographyAffected
Red Hat Enterprise Linux 8python-cryptographyAffected
Red Hat Enterprise Linux 9python3.12-cryptographyNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2255331python-cryptography: NULL-dereference when loading PKCS7 certificates

EPSS

Процентиль: 63%
0.00445
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 1 года назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

CVSS3: 5.9
nvd
больше 1 года назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.9
debian
больше 1 года назад

cryptography is a package designed to expose cryptographic primitives ...

suse-cvrf
больше 1 года назад

Security update for python-cryptography

EPSS

Процентиль: 63%
0.00445
Низкий

7.5 High

CVSS3