VDB
BDU%3A2024-02534
BDU%3A2024-02534
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функций load_pem_pkcs7_certificates() и load_der_pkcs7_certificates() пакет cryptography, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», АО «ИВК», Сообщество свободного программного обеспечения, ООО «НЦПР» | РЕД ОС (запись в едином реестре российских программ №3751), АЛЬТ СП 10, cryptography, МСВСфера |
Timeline
- Apr 3, 2024 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://github.com/pyca/cryptography/commit/f09c261ca10a31fe41b1262306db7f8f1da0e48a url
- https://github.com/pyca/cryptography/pull/9926 url
- https://github.com/pyca/cryptography/security/advisories/GHSA-jfhm-5ghh-2f97 url
- https://redos.red-soft.ru/support/secure/ url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2025:15874?lang=ru url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory