Количество 10
Количество 10
CVE-2018-10903
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
CVE-2018-10903
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
CVE-2018-10903
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
CVE-2018-10903
A flaw was found in python-cryptography versions between >=1.9.0 and < ...
openSUSE-SU-2018:3445-1
Security update for python-cryptography
SUSE-SU-2022:4044-1
Security update for python-cryptography, python-cryptography-vectors
SUSE-SU-2020:0792-1
Security update for python-cffi, python-cryptography
SUSE-SU-2020:0790-1
Security update for python-cffi, python-cryptography, python-xattr
SUSE-SU-2018:3392-1
Security update for python-cryptography
GHSA-fcf9-3qw3-gxmj
PyCA Cryptography vulnerable to GCM tag forgery
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-10903 A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage. | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад | |
CVE-2018-10903 A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage. | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад | |
CVE-2018-10903 A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage. | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад | |
CVE-2018-10903 A flaw was found in python-cryptography versions between >=1.9.0 and < ... | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад | |
openSUSE-SU-2018:3445-1 Security update for python-cryptography | 0% Низкий | больше 7 лет назад | ||
SUSE-SU-2022:4044-1 Security update for python-cryptography, python-cryptography-vectors | 0% Низкий | около 3 лет назад | ||
SUSE-SU-2020:0792-1 Security update for python-cffi, python-cryptography | 0% Низкий | почти 6 лет назад | ||
SUSE-SU-2020:0790-1 Security update for python-cffi, python-cryptography, python-xattr | 0% Низкий | почти 6 лет назад | ||
SUSE-SU-2018:3392-1 Security update for python-cryptography | 0% Низкий | больше 7 лет назад | ||
GHSA-fcf9-3qw3-gxmj PyCA Cryptography vulnerable to GCM tag forgery | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад |
Уязвимостей на страницу