Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-38325

Published: July 14, 2023Last modified: February 6, 2024

Description

The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Notes

Introduced in 40.0.0: https://github.com/pyca/cryptography/commit/aca8de845e751dd45fe4e48f8492f357d34d1861

Status

ProductReleasePackageStatus
Alpaquita LinuxStreampy3-cryptographyNot affected (41.0.3-r0)

References

ON THIS PAGE