Skip to content

x/vulndb: potential Go vuln in github.com/pyca/cryptography: CVE-2020-36242 #431

Closed
@GoVulnBot

Description

@GoVulnBot

CVE-2020-36242 references github.com/pyca/cryptography, which may be a Go module.

Description:
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

Links:

See doc/triage.md for instructions on how to triage this report.

module: github.com/pyca/cryptography
package: n/a
description: |
    In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
cves:
  - CVE-2020-36242
links:
    context:
      - https://github.com/pyca/cryptography/blob/master/CHANGELOG.rst
      - https://github.com/pyca/cryptography/compare/3.3.1...3.3.2
      - https://github.com/pyca/cryptography/issues/5615
      - https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/
      - https://www.oracle.com/security-alerts/cpuapr2022.html

Metadata

Metadata

Assignees

No one assigned

    Labels

    excluded: NOT_GO_CODEThis vulnerability does not refer to a Go module.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions