CVE-2020-36242 REJECTED

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

EPSS 1.27% · 79.4th percentile

Risk Scores

EPSS Score
1.27%
79.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSpython-cryptography0, 1.9-1, 2.1.3-3
Ubuntu:16.04:LTSpython-cryptography1.1.1-1ubuntu2, 1.2.3-1ubuntu0.2, 0
Ubuntu:20.04:LTSpython-cryptography0, 2.6.1-3.1, 2.6.1-4

Timeline

References

Open in Interactive Console →