CVE-2020-36242
CRITICAL9.1EPSS 1.6%PyCA Cryptography symmetrically encrypting large values can lead to integer overflow
發布日:2021/2/10修改日:2025/12/3
也稱為:ALPINE-CVE-2020-36242
描述
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
受影響套件(4)
- Alpine/py3-cryptographyfrom 0, < 3.3.2-r0
- Debian/python-cryptographyfrom 0, < 3.3.2-1
- PyPI/cryptography>= 3.1, < 3.3.2
- PyPI/cryptography>= 3.1, < 3.3.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
參考連結(16)
- ADVISORYhttps://github.com/advisories/GHSA-rhm9-p9w5-fwm7
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-36242
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2020-36242
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-36242
- PATCHhttps://github.com/pyca/cryptography
- WEBhttps://github.com/pyca/cryptography/blob/master/CHANGELOG.rst
- WEBhttps://github.com/pyca/cryptography/commit/82b6ce28389f0a317bc55ba2091a74b346db7cae
- WEBhttps://github.com/pyca/cryptography/compare/3.3.1...3.3.2
- WEBhttps://github.com/pyca/cryptography/issues/5615
- WEBhttps://github.com/pyca/cryptography/security/advisories/GHSA-rhm9-p9w5-fwm7
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2021-63.yaml
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/
- WEBhttps://www.oracle.com/security-alerts/cpuapr2022.html
- WEBhttps://www.oracle.com/security-alerts/cpujul2022.html