VDB
BDU%3A2023-02656
BDU%3A2023-02656
PUBLISHED
CVSS 6.400000095367432 MEDIUM
Уязвимость функции Cipher.update_into пакета cryptography интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность и доступность выходных данных
Risk Scores
CVSS 2.0
6.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», Fedora Project, Oracle Corp., NetApp Inc., Wazuh, Inc, АО "НППКТ", АО «ИВК», ООО «НЦПР» | Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, Red Hat Enterprise Linux, Debian GNU/Linux, Red Hat Software Collections, Red Hat Quay, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), OpenSUSE Leap, Fedora, openSUSE Leap Micro, Red Hat OpenShift Data Science (RHODS), cryptography, Red Hat Update Infrastructure for Cloud Providers, Red Hat Discovery, Red Hat Ansible Automation Platform, Communications Cloud Native Core Network Exposure Function, Oracle Communications Cloud Native Core Security Edge Protection Proxy, NetApp Converged Systems Advisor Agent, Wazuh, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), АЛЬТ СП 10, МСВСфера |
Timeline
- May 17, 2023 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://www.cybersecurity-help.cz/vdb/SB20230418133 url
- https://github.com/pyca/cryptography/pull/8230/commits/94a50a9731f35405f0357fa5f3b177d46a726ab3 url
- https://github.com/pyca/cryptography/security/advisories/GHSA-w7pp-m8wf-vj6r url
- https://access.redhat.com/security/cve/CVE-2023-23931 url
- https://www.suse.com/security/cve/CVE-2023-23931.html url
- https://bugzilla.suse.com/show_bug.cgi?id=1208036 url
- https://security-tracker.debian.org/tracker/CVE-2023-23931 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-749dd47c79 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YEWOQURWVFFOYSLMLALWX54SXYYKA5QR/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3DPI3KSRJPJPLUQ4XIGK6Z3PKN2RS4Q/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KU4ERFXTSWX22ZHW3435N535ZXC6B6KI/ url
- https://www.oracle.com/security-alerts/cpuapr2023.html?952634 url
- https://security.netapp.com/advisory/ntap-20230324-0007/ url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://redos.red-soft.ru/support/secure/ url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.8/ url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2023:6615?lang=ru url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2023-0303SE17MD advisory