Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-49083
HistoryNov 29, 2023 - 7:15 p.m.

CVE-2023-49083

2023-11-2919:15:07
Alpine Linux Development Team
security.alpinelinux.org
11
cryptography package
null-pointer dereference
segfault
denial of service
pkcs7 blob
dos
system stability
system availability
patch 41.0.6
python

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.1%

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling load_pem_pkcs7_certificates or load_der_pkcs7_certificates could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

OSVersionArchitecturePackageVersionFilename
Alpine3.18-communitynoarchpy3-cryptography= 41.0.3-r0UNKNOWN