漏洞信息详情
python-cryptography 安全漏洞
漏洞简介
python-cryptography是Cryptographic团队的一个应用于加密的 Python 代码库。
python-cryptography 存在安全漏洞,该漏洞源于定时oracle攻击进行RSA解密。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/pyca/cryptography/security/advisories/GHSA-hggm-jpg3-v476
参考网址
来源:MISC
链接:https://github.com/pyca/cryptography/pull/5507/commits/ce1bef6f1ee06ac497ca0c837fbd1c7ef6c2472b
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4283/
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2020-25659
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052024
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021060319
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-25659
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-cloud-private-is-vulnerable-to-a-python-vulnerability-cve-2020-25659/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-the-python-docker-and-icp-affect-ibm-spectrum-discover/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-watson-openscale-on-cloud-pak-for-data-is-impacted-by-cve-2020-25659/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1866
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2711
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2904
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162632/Red-Hat-Security-Advisory-2021-1608-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1933
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Python-Cryptography-information-disclosure-via-Decryption-33781
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162944/Red-Hat-Security-Advisory-2021-2239-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3551
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4306/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1741
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-the-python-python-cryptography-and-urllib3-affect-ibm-spectrum-discover/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerability-in-python-affects-ibm-spectrum-protect-plus-microsoft-file-systems-backup-and-restore-cve-2020-25659/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163209/Red-Hat-Security-Advisory-2021-2479-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2160
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/159803/Ubuntu-Security-Notice-USN-4613-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163941/Red-Hat-Security-Advisory-2021-3254-01.html
受影响实体
暂无
补丁
- Python 安全漏洞的修复措施<!--2020-10-25-->
还没有评论,来说两句吧...