ZeroHour

CVE-2020-36242

PoC
CVSS 3.1
9.1 critical
EPSS
7%p94
Published
()
Modified
Description

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

Vendors
cryptography.iofedoraprojectoracle
Products
cryptography, fedora, communications cloud native core network function cloud native environment
Weakness
CWE-190, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.