In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cryptography.io
Cryptography.io cryptography |
|
CPEs | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* | |
Vendors & Products |
Cryptography Project
Cryptography Project cryptography |
Cryptography.io
Cryptography.io cryptography |
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-02-07T19:50:57
Updated: 2024-08-04T17:23:09.814Z
Reserved: 2021-02-07T00:00:00
Link: CVE-2020-36242
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-07T20:15:12.090
Modified: 2024-11-21T05:29:08.287
Link: CVE-2020-36242
Redhat