Описание
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to set_cookie_generate_callback returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 25.3.0-1ubuntu1 |
| esm-infra-legacy/trusty | not-affected | |
| esm-infra-legacy/xenial | not-affected | |
| esm-infra/bionic | not-affected | |
| esm-infra/focal | not-affected | |
| esm-infra/xenial | not-affected | |
| jammy | not-affected | 21.0.0-1 |
| noble | released | 23.2.0-1ubuntu0.1 |
| questing | released | 25.0.0-1ubuntu0.1 |
| upstream | released | 26.0.0 |
Показывать по
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...
EPSS
9.8 Critical
CVSS3