CVE-2023-49083

Severity
7.5HIGH
EPSS
1.3%
top 20.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 29
Latest updateJul 15

Description

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Calling `load_pem_pkcs7_certificates` or `load_der_pkcs7_certificates` could lead to a NULL-pointer dereference and segfault. Exploitation of this vulnerability poses a serious risk of Denial of Service (DoS) for any application attempting to deserialize a PKCS7 blob/certificate. The consequences extend to potential disruptions in system availability and stability. This vulnerability has been

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages4 packages

Debianpython-cryptography< 3.3.2-1+deb11u1+3
PyPIcryptography3.141.0.6
NVDcryptography.io/cryptography3.141.0.6
CVEListV5pyca/cryptography>= 3.1, < 41.0.6

Patches

🔴Vulnerability Details

5
OSV
python-cryptography vulnerabilities2023-12-06
OSV
CVE-2023-49083: cryptography is a package designed to expose cryptographic primitives and recipes to Python developers2023-11-29
CVEList
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates2023-11-29
OSV
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates2023-11-28
GHSA
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates2023-11-28

📋Vendor Advisories

6
Oracle
Oracle Oracle Analytics Risk Matrix: Pipeline Test Failures (Cryptography) — CVE-2023-490832024-07-15
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (Cryptography) — CVE-2023-490832024-04-15
Ubuntu
python-cryptography vulnerabilities2023-12-06
Red Hat
python-cryptography: NULL-dereference when loading PKCS7 certificates2023-11-28
Microsoft
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates2023-11-14