Logo
vulnerabilityCVE-2023-49083
Name
CVE-2023-49083
Source
NVD ( link)Debian ( link)
Description
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-cryptography
Patched

Vulnerability Ratings#


5.9
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
49.0.0
Not Affected
yocto
scarthgap
42.0.5
Not Affected

Resolved with patches#


python3-cryptography (yocto:kirkstone)

#
Title
Author
Resolve
1
Fixed crash when loading a PKCS#7 bundle with no certificates
Alex Gaynor <alex.gaynor@gmail.com>
CVE-2023-49083