CVE-2020-36242

critical
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.

References

https://github.com/pyca/cryptography/issues/5615

https://github.com/pyca/cryptography/blob/master/CHANGELOG.rst

https://github.com/pyca/cryptography/compare/3.3.1...3.3.2

https://lists.fedoraproject.org/archives/list/[email protected]/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/

Details

Source: MITRE

Published: 2021-02-07

Updated: 2021-07-21

Type: CWE-190

Risk Information

CVSS v2

Base Score: 6.4

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Impact Score: 4.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 9.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Impact Score: 5.2

Exploitability Score: 3.9

Severity: CRITICAL

Tenable Plugins

View all (17 total)

IDNameProductFamilySeverity
152781RHEL 7 : rh-python38 (RHSA-2021:3254)NessusRed Hat Local Security Checks
critical
152311EulerOS 2.0 SP9 : python-cryptography (EulerOS-SA-2021-2278)NessusHuawei Local Security Checks
critical
152275EulerOS 2.0 SP9 : python-cryptography (EulerOS-SA-2021-2252)NessusHuawei Local Security Checks
critical
151560EulerOS Virtualization 2.9.1 : python-cryptography (EulerOS-SA-2021-2178)NessusHuawei Local Security Checks
critical
151546EulerOS Virtualization 2.9.0 : python-cryptography (EulerOS-SA-2021-2208)NessusHuawei Local Security Checks
critical
150439Photon OS 1.0: Python PHSA-2021-1.0-0400NessusPhotonOS Local Security Checks
critical
149969Oracle Linux 8 : python-cryptography (ELSA-2021-1608)NessusOracle Linux Local Security Checks
critical
149836Photon OS 4.0: Python3 PHSA-2021-4.0-0027NessusPhotonOS Local Security Checks
critical
149831Photon OS 2.0: Python PHSA-2021-2.0-0347NessusPhotonOS Local Security Checks
critical
149819Photon OS 3.0: Python PHSA-2021-3.0-0239NessusPhotonOS Local Security Checks
critical
149778CentOS 8 : python-cryptography (CESA-2021:1608)NessusCentOS Local Security Checks
critical
149686RHEL 8 : python-cryptography (RHSA-2021:1608)NessusRed Hat Local Security Checks
critical
147060SUSE SLES15 Security Update : python-cryptography (SUSE-SU-2021:0696-1)NessusSuSE Local Security Checks
critical
146966SUSE SLES12 Security Update : python-cryptography (SUSE-SU-2021:0675-1)NessusSuSE Local Security Checks
critical
146923SUSE SLED15 / SLES15 Security Update : python-cryptography (SUSE-SU-2021:0594-1)NessusSuSE Local Security Checks
critical
146898openSUSE Security Update : python-cryptography (openSUSE-2021-349)NessusSuSE Local Security Checks
critical
146462Fedora 33 : python-cryptography (2021-8e36e7ed1a)NessusFedora Local Security Checks
critical