Release | Version |
---|---|
buster | 2.6.1-3+deb10u2 |
buster (security) | 2.6.1-3+deb10u4 |
bullseye | 3.3.2-1 |
bookworm | 38.0.4-3 |
bookworm (security) | 38.0.4-3~deb12u1 |
trixie | 38.0.4-4 |
sid | 38.0.4-4 |
Bug | buster | bullseye | bookworm | trixie | sid | Description |
---|---|---|---|---|---|---|
CVE-2023-23931 | fixed | vulnerable (no DSA) | fixed | fixed | fixed | cryptography is a package designed to expose cryptographic primitives ... |
CVE-2020-36242 | vulnerable (no DSA) | fixed | fixed | fixed | fixed | In the cryptography package before 3.3.2 for Python, certain sequences ... |
CVE-2020-25659 | vulnerable (no DSA) | fixed | fixed | fixed | fixed | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks ... |
Bug | Description |
---|---|
CVE-2023-38325 | The cryptography package before 41.0.2 for Python mishandles SSH certi ... |
CVE-2018-10903 | A flaw was found in python-cryptography versions between >=1.9.0 and < ... |
CVE-2016-9243 | HKDF in cryptography before 1.5.2 returns an empty byte-string if used ... |
DSA / DLA | Description |
---|---|
DLA-3331-2 | python-cryptography - regression update |
DLA-3331-1 | python-cryptography - security update |