Source: python-cryptography
Version: 38.0.4-4
Severity: important
Tags: security upstream
Forwarded: https://github.com/pyca/cryptography/pull/9926
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>

Hi,

The following vulnerability was published for python-cryptography.

CVE-2023-49083[0]:
| cryptography is a package designed to expose cryptographic
| primitives and recipes to Python developers. Calling
| `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could
| lead to a NULL-pointer dereference and segfault. Exploitation of
| this vulnerability poses a serious risk of Denial of Service (DoS)
| for any application attempting to deserialize a PKCS7
| blob/certificate. The consequences extend to potential disruptions
| in system availability and stability. This vulnerability has been
| patched in version 41.0.6.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-49083
    https://www.cve.org/CVERecord?id=CVE-2023-49083
[1] https://github.com/pyca/cryptography/pull/9926
[2] https://github.com/pyca/cryptography/security/advisories/GHSA-jfhm-5ghh-2f97

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to