AIX Open Source

AIX Open Source

Share your experiences and connect with fellow developers to discover how to build and manage open source software for the AIX operating system

 View Only
  • 1.  current version of cryptography is affected by CVE-2023-23931

    Posted Wed January 10, 2024 06:37 PM

    Hi team,

    In a security scan I got the following vulnerability "CVE-2023-23931", the affected package is "cryptography".

    Looking into the change log (https://cryptography.io/en/latest/changelog/#v39-0-1), found that the vulnerability was fixed in the following version:

    39.0.1 - 2023-02-07

    • SECURITY ISSUE - Fixed a bug where Cipher.update_into accepted Python buffer protocol objects, but allowed immutable buffers. CVE-2023-23931

    • Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.8.

    Looking into the available package of "cryptography" in the Aix Tool box (AIX Toolbox for Open Source Software : Downloads alpha

    Ibm remove preview
    AIX Toolbox for Open Source Software : Downloads alpha
    AIX Toolbox for Open Source Software contains a collection of open source and GNU software built for AIX IBM Systems. These tools provide the basis of the development environment of choice for many Linux application developers.
    View this on Ibm >

    )

    The latest version is the following:

    Is there a plan to deliver a new version of "cryptography" to fix the vulnerability?



    ------------------------------
    LUIS ABDEL AGUILAR JURADO
    ------------------------------


  • 2.  RE: current version of cryptography is affected by CVE-2023-23931

    Posted Thu January 11, 2024 02:17 AM

    Hi Luis,

    The CVE-2023-23931 is backported to the  version python3.9-cryptography-3.4.7-

    You can refer the spec file from the toolbox link below.

    public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/SPECS/python3.9-cryptography-3.4.7-4.spec



    ------------------------------
    Harshith K A
    ------------------------------



  • 3.  RE: current version of cryptography is affected by CVE-2023-23931

    Posted Thu January 11, 2024 11:41 AM

    Thanks for the clarification

    There is also another vulnerability reported: CVE-2023-38325 [https://www.cve.org/CVERecord?id=CVE-2023-38325]

    I was not able to find that vulnerability in the current cryptography package.

    Is there a plan to deliver a new version of "cryptography" to fix the vulnerability?



    ------------------------------
    LUIS ABDEL AGUILAR JURADO
    ------------------------------



  • 4.  RE: current version of cryptography is affected by CVE-2023-23931

    Posted Fri January 12, 2024 01:41 AM

    The CVE-2023-38325  is not affecting the toolbox version python3.9-cryptography-3.4.7-



    ------------------------------
    Harshith K A
    ------------------------------