Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 769419 (CVE-2020-36242) - <dev-python/cryptography-3.3.2: certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow
Summary: <dev-python/cryptography-3.3.2: certain sequences of update calls to symmetri...
Status: CONFIRMED
Alias: CVE-2020-36242
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A4 [glsa?]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-02-08 08:31 UTC by Michał Górny
Modified: 2022-06-02 22:06 UTC (History)
1 user (show)

See Also:
Package list:
dev-python/cryptography-3.3.2
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2021-02-08 08:31:34 UTC
* **SECURITY ISSUE:** Fixed a bug where certain sequences of ``update()`` calls
  when symmetrically encrypting very large payloads (>2GB) could result in an
  integer overflow, leading to buffer overflows. *CVE-2020-36242*
Comment 1 NATTkA bot gentoo-dev 2021-02-08 08:32:52 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-02-08 08:44:56 UTC Comment hidden (obsolete)
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-08 17:26:53 UTC
x86 done
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-09 06:16:49 UTC
sparc done
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-11 07:54:30 UTC
amd64 done
Comment 6 Sergei Trofimovich (RETIRED) gentoo-dev 2021-02-11 23:00:05 UTC
ppc64 stable
Comment 7 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-13 17:57:45 UTC
arm64 done
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-14 19:44:22 UTC
arm done
Comment 9 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-02-15 10:49:13 UTC
ppc done
Comment 10 Rolf Eike Beer archtester 2021-02-16 20:15:01 UTC
hppa stable
Comment 11 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-05 22:25:53 UTC
s390 done

all arches done
Comment 12 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-04-06 01:48:06 UTC
Please cleanup.
Comment 13 Larry the Git Cow gentoo-dev 2021-04-06 06:28:28 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f4caeb851ad299b29220092be27856dd0e4c8d57

commit f4caeb851ad299b29220092be27856dd0e4c8d57
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: 2021-04-06 06:27:39 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2021-04-06 06:27:49 +0000

    dev-python/cryptography: Remove old
    
    Closes: https://bugs.gentoo.org/769419
    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 dev-python/cryptography/Manifest                  |  4 --
 dev-python/cryptography/cryptography-3.2.1.ebuild | 67 -----------------------
 dev-python/cryptography/cryptography-3.3.1.ebuild | 67 -----------------------
 3 files changed, 138 deletions(-)
Comment 14 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2021-04-06 06:28:56 UTC
Sry, wrong tag.
Comment 15 NATTkA bot gentoo-dev 2021-05-18 11:44:29 UTC
Unable to check for sanity:

> no match for package: dev-python/cryptography-3.3.2