Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-38325
HistoryJul 14, 2023 - 12:00 a.m.

CVE-2023-38325

2023-07-1400:00:00
ubuntu.com
ubuntu.com
12
cryptography package
python
ssh certificates
critical options
openssh
ubuntu
vulnerable version
bug
cve-2023-38325
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

47.6%

The cryptography package before 41.0.2 for Python mishandles SSH
certificates that have critical options.

Bugs

Notes

Author Note
mdeslaur OpenSSH certificate parsing was introduced in 40.0.0, Ubuntu has no vulnerable versions

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

47.6%