漏洞信息详情
python-cryptography 安全漏洞
漏洞简介
python-cryptography是Cryptographic团队的一个应用于加密的 Python 代码库。
python-cryptography package before 3.3.2 for Python 存在安全漏洞,该漏洞源于导致整数溢出和缓冲区溢出。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/pyca/cryptography/compare/3.3.1...3.3.2
参考网址
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/
来源:MISC
链接:https://github.com/pyca/cryptography/issues/5615
来源:CONFIRM
链接:https://github.com/pyca/cryptography/blob/master/CHANGELOG.rst
来源:CONFIRM
链接:https://github.com/pyca/cryptography/compare/3.3.1...3.3.2
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021052024
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021060319
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Python-Cryptography-integer-overflow-via-Multi-GB-Values-Symmetrically-Encryption-34572
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1866
来源:www.ibm.com
链接:https://www.ibm.com/support/pages/node/6492741
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2711
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0758
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2904
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0723
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162632/Red-Hat-Security-Advisory-2021-1608-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1933
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0790
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162944/Red-Hat-Security-Advisory-2021-2239-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1741
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-the-python-python-cryptography-and-urllib3-affect-ibm-spectrum-discover/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-36242
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163209/Red-Hat-Security-Advisory-2021-2479-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2160
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/163941/Red-Hat-Security-Advisory-2021-3254-01.html
受影响实体
暂无
补丁
- cryptography package 安全漏洞的修复措施<!--2021-2-7-->
还没有评论,来说两句吧...