Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-6129 #1362

Closed
kinoute opened this issue Sep 4, 2024 · 1 comment
Closed

CVE-2023-6129 #1362

kinoute opened this issue Sep 4, 2024 · 1 comment

Comments

@kinoute
Copy link

kinoute commented Sep 4, 2024

Hello, safety reports this vulnerability in pyopenssl:

-> Vulnerability found in pyopenssl version 24.2.1
   Vulnerability ID: 65213
   Affected spec: >=22.0.0
   ADVISORY: CVE-2023-6129 affects PyOpenSSL versions starting from
   22.0.0 due to a vulnerability in the POLY1305 MAC algorithm on PowerPC
   CPUs. This issue could lead to state corruption in applications, causing
   inaccurate outcomes or service disruptions. Attackers need specific
   conditions to exploit this flaw, including the ability to manipulate the
   algorithm's use and reliance on certain system registers by the
   application.
   CVE-2023-6129
   For more information about this vulnerability, visit
   https://data.safetycli.com/v/65213/97c
   To ignore this vulnerability, use PyUp vulnerability id 65213 in safety’s
   ignore command-line argument or add the ignore to your safety policy file.
@alex
Copy link
Member

alex commented Sep 4, 2024

Dupe of #1300

@alex alex closed this as completed Sep 4, 2024
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Dec 4, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

No branches or pull requests

2 participants