Summary: | <dev-python/cryptography-39.0.1: Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Michał Górny <mgorny> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | ajak |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://github.com/pyca/cryptography/security/advisories/GHSA-w7pp-m8wf-vj6r | ||
Whiteboard: | A3 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 893574 | ||
Bug Blocks: |
Description
Michał Górny
2023-02-08 05:28:51 UTC
Thanks! Can't cleanup because of bug 893522. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=860a9047ef51635cb4b93e2528b25d923dce8d58 commit 860a9047ef51635cb4b93e2528b25d923dce8d58 Author: Arthur Zamarin <arthurzam@gentoo.org> AuthorDate: 2023-04-21 15:43:44 +0000 Commit: Arthur Zamarin <arthurzam@gentoo.org> CommitDate: 2023-04-21 15:44:26 +0000 dev-python/cryptography: drop 38.0.4 Bug: https://bugs.gentoo.org/893576 Signed-off-by: Arthur Zamarin <arthurzam@gentoo.org> dev-python/cryptography/Manifest | 25 ---- dev-python/cryptography/cryptography-38.0.4.ebuild | 143 --------------------- 2 files changed, 168 deletions(-) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=c64e048a91b0aa0d481f453db2b0de77a5123fc4 commit c64e048a91b0aa0d481f453db2b0de77a5123fc4 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-07-01 05:59:02 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2024-07-01 06:09:25 +0000 [ GLSA 202407-06 ] cryptography: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/769419 Bug: https://bugs.gentoo.org/864049 Bug: https://bugs.gentoo.org/893576 Bug: https://bugs.gentoo.org/918685 Bug: https://bugs.gentoo.org/925120 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202407-06.xml | 49 +++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) |