安全公告详情

NS-SA-2025-0151

2025-07-25 16:49:52

简介

important: python-cryptography/python-oauthlib security update

严重级别

important

主题

An update for python-cryptography/python-oauthlib is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

python-cryptography:
python-oauthlib:


Security Fix(es):
python-cryptography: A null-pointer dereference vulnerability was found in python-cryptography during the loading of PKCS7 certificates. Invoking "load_pem_pkcs7_certificates" or "load_der_pkcs7_certificates" can trigger this issue and lead to subsequent segmentation fault and result in a Denial of Service (DoS) for any application aiming to deserialize a PKCS7 blob or certificate. The potential impact includes disruptions in system availability and stability.(CVE-2023-49083)
python-cryptography: A vulnerability was found in python-cryptography. In affected versions, `Cipher.update_into` would accept Python objects which implement the buffer protocol but provide only immutable buffers. This issue allows immutable objects (such as `bytes`) to be mutated, thus violating the fundamental rules of Python, resulting in corrupted output.(CVE-2023-23931)
python-cryptography: A flaw was discovered in python-cryptography. A NULL pointer dereference can be triggered when a PKCS#12 key and certificate do not match. Specifically, if the pkcs12.serialize_key_and_certificates function is called with a non-matching certificate and private key and an encryption algorithm with hmac_hash set, the Python process may crash, leading to a denial of service.(CVE-2024-26130)
python-cryptography: bugfix
python-oauthlib: A flaw was found in python-oauthlib. This flaw allows an attacker providing a malicious redirect URI to cause a denial of service to OAuthLib's web application.(CVE-2022-36087)
python-oauthlib: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.03B8.

影响组件

  • python-cryptography
  • python-oauthlib

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["python3-cryptography-42.0.5-2.zncgsl7.4.x86_64.rpm"],"source":"python-cryptography-42.0.5-2.zncgsl7.4.src.rpm"},{"binary":["python3-oauthlib-3.2.2-2.zncgsl7.3.noarch.rpm"],"source":"python-oauthlib-3.2.2-2.zncgsl7.3.src.rpm"}]}]}

CVE

参考