Логотип exploitDog
bind: "CVE-2023-23931"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-23931"

Количество 16

Количество 16

ubuntu логотип

CVE-2023-23931

больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2023-23931

больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23931

больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 4.8
EPSS: Низкий
msrc логотип

CVE-2023-23931

12 месяцев назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23931

больше 2 лет назад

cryptography is a package designed to expose cryptographic primitives ...

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1767-1

около 2 лет назад

Security update for python-cryptography

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1763-1

около 2 лет назад

Security update for python-cryptography

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0837-1

около 2 лет назад

Security update for python-cffi

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0737-1

больше 2 лет назад

Security update for python-cryptography

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0722-1

больше 2 лет назад

Security update for python-cryptography

EPSS: Низкий
github логотип

GHSA-w7pp-m8wf-vj6r

больше 2 лет назад

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2023-7096

больше 1 года назад

ELSA-2023-7096: python-cryptography security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6615

больше 1 года назад

ELSA-2023-6615: python-cryptography security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2023-02656

больше 2 лет назад

Уязвимость функции Cipher.update_into пакета cryptography интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность выходных данных

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-2985

около 1 года назад

ELSA-2024-2985: python39:3.9 and python39-devel:3.9 security update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20230620-06

почти 2 года назад

Множественные уязвимости python3-cryptography

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-23931

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-23931

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23931

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 6.5
1%
Низкий
12 месяцев назад
debian логотип
CVE-2023-23931

cryptography is a package designed to expose cryptographic primitives ...

CVSS3: 4.8
1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1767-1

Security update for python-cryptography

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1763-1

Security update for python-cryptography

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0837-1

Security update for python-cffi

1%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0737-1

Security update for python-cryptography

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0722-1

Security update for python-cryptography

1%
Низкий
больше 2 лет назад
github логотип
GHSA-w7pp-m8wf-vj6r

Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2023-7096

ELSA-2023-7096: python-cryptography security update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2023-6615

ELSA-2023-6615: python-cryptography security update (MODERATE)

больше 1 года назад
fstec логотип
BDU:2023-02656

Уязвимость функции Cipher.update_into пакета cryptography интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность выходных данных

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2024-2985

ELSA-2024-2985: python39:3.9 and python39-devel:3.9 security update (MODERATE)

около 1 года назад
redos логотип
ROS-20230620-06

Множественные уязвимости python3-cryptography

CVSS3: 9.1
почти 2 года назад

Уязвимостей на страницу