VDB
BDU%3A2024-03237
BDU%3A2024-03237
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функций pkcs12.serialize_key_and_certificates пакета cryptography интерпретатора языка программирования Python, позволяющая нарушителю вызвать сбой процесса Python
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», АО «ИВК», Сообщество свободного программного обеспечения | РЕД ОС (запись в едином реестре российских программ №3751), АЛЬТ СП 10, cryptography |
Timeline
- Apr 25, 2024 CVE Published
- Apr 8, 2025 CVE Updated
References
- https://github.com/pyca/cryptography/pull/10423 url
- https://redos.red-soft.ru/support/secure/ url
- https://safe-surf.ru/upload/VULN-new/VULN.2024-04-19.1.pdf url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://github.com/pyca/cryptography/security/advisories/GHSA-6vqw-3v5j-54x4 advisory
- https://github.com/pyca/cryptography/commit/97d231672763cdb5959a3b191e692a362f1b9e55 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory