VDB

GCVE-VVD-MAGEIA-2023-71

GCVE-VVD-MAGEIA-2023-71
Advisory Published
Vulnetix · Advisory published September 24, 2023
Cipher.update_into would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as 'bytes') to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. (CVE-2023-23931)

Affected Products

VendorProductVersionsPlatforms
Mageiaphp0 (affected), 8.2.10-1.mga9 (unaffected)
Mageiapython-cryptography0 (affected), 3.3.1-1.2.mga8 (unaffected), 0 (affected), 3.3.1-1.2.mga8 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›