Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-50782

Published: December 14, 2023Last modified: February 14, 2024

Description

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Notes

The fix in openssl (libcrypto3) package.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSopensslFixed (3.0.12-r5)
py3-cryptographyWill not fix (38.0.3-r1)
StreamopensslFixed (3.1.5-r6)
py3-cryptographyWill not fix (39.0.2-r0)

References

ON THIS PAGE