First published: Mon Mar 04 2024(Updated: )
Hubert Kario discovered that python-cryptography incorrectly handled errors returned by the OpenSSL API when processing incorrect padding in RSA PKCS#1 v1.5. A remote attacker could possibly use this issue to expose confidential or sensitive information. (CVE-2023-50782) It was discovered that python-cryptography incorrectly handled memory operations when processing mismatched PKCS#12 keys. A remote attacker could possibly use this issue to cause python-cryptography to crash, leading to a denial of service. This issue only affected Ubuntu 23.10. (CVE-2024-26130)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/python3-cryptography | <38.0.4-4ubuntu0.23.10.2 | 38.0.4-4ubuntu0.23.10.2 |
Ubuntu Ubuntu | =23.10 | |
All of | ||
ubuntu/python3-cryptography | <3.4.8-1ubuntu2.2 | 3.4.8-1ubuntu2.2 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/python-cryptography | <2.8-3ubuntu0.3 | 2.8-3ubuntu0.3 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python3-cryptography | <2.8-3ubuntu0.3 | 2.8-3ubuntu0.3 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/python-cryptography | <2.1.4-1ubuntu1.4+esm1 | 2.1.4-1ubuntu1.4+esm1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/python3-cryptography | <2.1.4-1ubuntu1.4+esm1 | 2.1.4-1ubuntu1.4+esm1 |
Ubuntu Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.