rpm package
suse/python-aliyun-python-sdk-core&distro=SUSE Linux Enterprise Module for Public Cloud 15 SP4
pkg:rpm/suse/python-aliyun-python-sdk-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-52323 | — | < 2.15.1-150400.10.3.1 | 2.15.1-150400.10.3.1 | Jan 5, 2024 | PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. | ||
| CVE-2020-36242 | — | < 2.13.30-150100.3.7.5 | 2.13.30-150100.3.7.5 | Feb 7, 2021 | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class. |
- CVE-2023-52323Jan 5, 2024affected < 2.15.1-150400.10.3.1fixed 2.15.1-150400.10.3.1
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
- CVE-2020-36242Feb 7, 2021affected < 2.13.30-150100.3.7.5fixed 2.13.30-150100.3.7.5
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.