In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cryptography.io
Cryptography.io cryptography |
|
CPEs | cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:* | |
Vendors & Products |
Cryptography Project
Cryptography Project cryptography |
Cryptography.io
Cryptography.io cryptography |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T17:23:09.814Z
Reserved: 2021-02-07T00:00:00
Link: CVE-2020-36242

No data.

Status : Modified
Published: 2021-02-07T20:15:12.090
Modified: 2024-11-21T05:29:08.287
Link: CVE-2020-36242
