OESA-2023-1887
Dashboard / Vulnerabilities / OESA-2023-1887
Summary: python-cryptography security update
Details: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Security Fix(es): cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.(CVE-2023-49083)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1887, https://nvd.nist.gov/vuln/detail/CVE-2023-49083
Affected packages
Package
Name: python-cryptography
Purl: pkg:rpm/openEuler/python-cryptography&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
