Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-49083
HistoryNov 29, 2023 - 7:15 p.m.

Null pointer dereference

2023-11-2919:15:00
PRIOn knowledge base
www.prio-n.com
15
cryptography package
null-pointer dereference
segfault
denial of service
pkcs7 blob
system availability
stability
vulnerability patch

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

25.1%

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling load_pem_pkcs7_certificates or load_der_pkcs7_certificates could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been patched in version 41.0.6.

CPENameOperatorVersion
cryptographyge3.1
cryptographylt41.0.6