VDB
Sign up
HIGH7.5

PYSEC-2023-254

Quick fix

PYSEC-2023-254 — cryptography: upgrade to the fixed version with the command below.

pip install --upgrade 'cryptography>=f09c261ca10a31fe41b1262306db7f8f1da0e48a'

Details

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cryptography
Introduced in: 0Fixed in: f09c261ca10a31fe41b1262306db7f8f1da0e48a
Fixpip install --upgrade 'cryptography>=f09c261ca10a31fe41b1262306db7f8f1da0e48a'

References