Publish GHSA-6vqw-3v5j-54x4

This commit is contained in:
advisory-database[bot]
2024-02-21 22:47:00 +00:00
parent ce0e268ed1
commit 16cc80ea9e
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6vqw-3v5j-54x4",
"modified": "2024-02-21T19:33:17Z",
"modified": "2024-02-21T22:45:34Z",
"published": "2024-02-21T18:04:40Z",
"aliases": [
"CVE-2024-26130"
],
"summary": "cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override",
"summary": "cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override",
"details": "If `pkcs12.serialize_key_and_certificates` is called with both:\n\n1. A certificate whose public key did not match the provided private key\n2. An `encryption_algorithm` with `hmac_hash` set (via `PrivateFormat.PKCS12.encryption_builder().hmac_hash(...)`\n\nThen a NULL pointer dereference would occur, crashing the Python process.\n\nThis has been resolved, and now a `ValueError` is properly raised.\n\nPatched in https://github.com/pyca/cryptography/pull/10423",
"severity": [
{