VDB

CVE-2020-36242

CVE-2020-36242 REJECTED CVSS 9.100000381469727 CRITICAL

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

EPSS 6.72% · 93.5th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
6.72%
93.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSpython-cryptography0, 1.9-1, 2.1.3-3
Ubuntu:16.04:LTSpython-cryptography1.2.3-1ubuntu0.2, 1.1.1-1, 1.1.1-1ubuntu1
Ubuntu:20.04:LTSpython-cryptography2.6.1-3.1, 2.6.1-4, 2.6.1-4ubuntu1

Timeline

  • CVE Published
  • Apr 8, 2021 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Feb 13, 2025 PoC Published
  • Mar 18, 2025 EPSS Score
  • Mar 19, 2025 EPSS Score
  • Mar 24, 2025 EPSS Score
  • Mar 25, 2025 EPSS Score
  • Mar 28, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›