CVE-2023-38325
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
02 / AFFECTED SOFTWARE
Affected packages
3 explicit affected versions
5 explicit affected versions
5 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38325.json
- https://github.com/pyca/cryptography/compare/41.0.1...41.0.2
- https://github.com/pyca/cryptography/issues/9207
- https://github.com/pyca/cryptography/pull/9208
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMCCTYY3CSNQBFFYYC5DAV6KATHWCUZK/
- https://nvd.nist.gov/vuln/detail/CVE-2023-38325
- https://pypi.org/project/cryptography/#history
- https://security.netapp.com/advisory/ntap-20230824-0010/
- https://github.com/advisories/GHSA-cf7p-gm2m-833m
- https://github.com/pyca/cryptography
- https://github.com/pyca/cryptography/commit/1ca7adc97b76a9dfbd3d850628b613eb93b78fc3
- https://github.com/pyca/cryptography/pull/7960
- https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2023-112.yaml
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMCCTYY3CSNQBFFYYC5DAV6KATHWCUZK
- https://lists.fedoraproject.org/archives/list/[email protected]/message/NMCCTYY3CSNQBFFYYC5DAV6KATHWCUZK
- https://security.netapp.com/advisory/ntap-20230824-0010