Original Message:
Sent: Thu January 11, 2024 11:40 AM
From: LUIS ABDEL AGUILAR JURADO
Subject: current version of cryptography is affected by CVE-2023-23931
Thanks for the clarification
There is also another vulnerability reported: CVE-2023-38325 [https://www.cve.org/CVERecord?id=CVE-2023-38325]
I was not able to find that vulnerability in the current cryptography package.
Is there a plan to deliver a new version of "cryptography" to fix the vulnerability?
------------------------------
LUIS ABDEL AGUILAR JURADO
Original Message:
Sent: Thu January 11, 2024 02:17 AM
From: Harshith K A
Subject: current version of cryptography is affected by CVE-2023-23931
Hi Luis,
The CVE-2023-23931 is backported to the version python3.9-cryptography-3.4.7-4
You can refer the spec file from the toolbox link below.
public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/SPECS/python3.9-cryptography-3.4.7-4.spec
------------------------------
Harshith K A
Original Message:
Sent: Wed January 10, 2024 06:36 PM
From: LUIS ABDEL AGUILAR JURADO
Subject: current version of cryptography is affected by CVE-2023-23931
Hi team,
In a security scan I got the following vulnerability "CVE-2023-23931", the affected package is "cryptography".
Looking into the change log (https://cryptography.io/en/latest/changelog/#v39-0-1), found that the vulnerability was fixed in the following version:
39.0.1 - 2023-02-07
SECURITY ISSUE - Fixed a bug where Cipher.update_into
accepted Python buffer protocol objects, but allowed immutable buffers. CVE-2023-23931
Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.0.8.
Looking into the available package of "cryptography" in the Aix Tool box (AIX Toolbox for Open Source Software : Downloads alpha
Ibm | remove preview |
| AIX Toolbox for Open Source Software : Downloads alpha | AIX Toolbox for Open Source Software contains a collection of open source and GNU software built for AIX IBM Systems. These tools provide the basis of the development environment of choice for many Linux application developers. | View this on Ibm > |
|
|
)
The latest version is the following:

Is there a plan to deliver a new version of "cryptography" to fix the vulnerability?
------------------------------
LUIS ABDEL AGUILAR JURADO
------------------------------