FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-11-25 08:52:18 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
9e2d0dcf-9926-11e8-a92d-0050562a4d7bpy-cryptography -- tag forgery vulnerability

The Python Cryptographic Authority (PyCA) project reports:

finalize_with_tag() allowed tag truncation by default which can allow tag forgery in some cases. The method now enforces the min_tag_length provided to the GCM constructor


Discovery 2018-07-17
Entry 2018-08-06
py27-cryptography
py34-cryptography
py35-cryptography
py36-cryptography
py37-cryptography
< 2.3

CVE-2018-10903
c1a8ed1c-2814-4260-82aa-9e37c83aac93py-cryptography -- includes a vulnerable copy of OpenSSL

pyca/cryptography's wheels include a statically linked copy of OpenSSL.

The versions of OpenSSL included in cryptography 0.8.1-39.0.0 are vulnerable to a security issue.

More details about the vulnerabilities themselves can be found in https://www.openssl.org/news/secadv/20221213.txt and https://www.openssl.org/news/secadv/20230207.txt.

If you are building cryptography source ("sdist") then you are responsible for upgrading your copy of OpenSSL.

Only users installing from wheels built by the cryptography project (i.e., those distributed on PyPI) need to update their cryptography versions.


Discovery 2023-02-08
Entry 2023-04-10
py37-cryptography
py38-cryptography
py39-cryptography
py310-cryptography
py311-cryptography
< 39.0.1

CVE-2023-0286
https://osv.dev/vulnerability/GHSA-x4qr-2fvf-3mr5