Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Mageia 8 MGASA-2021-0130 Critical: Python-Cryptography Buffer Overflow

mageia
Calendar Grey March 11, 2021
Dist Mageia Esm H88
The recent update to the python-cryptography library in Mageia addresses significant vulnerabilities related to integer and buffer overflow problems.
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overf...

Summary

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow (CVE-2020-36242).

References

- https://bugs.mageia.org/show_bug.cgi?id=28384

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/

- https://www.cve.org/CVERecord?id=CVE-2020-36242

Resolution

SRPMS

- 8/core/python-cryptography-3.3.1-1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0129.html
Type: security
CVE: CVE-2020-36242

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here