Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-23931
Description:cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and resulting in corrupted output. This now correctly raises an exception. This issue has been present since `update_into` was originally introduced in cryptography 1.8.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2023.2466   1.3.6.1.4.1.25623.1.1.2.2023.1827   1.3.6.1.4.1.25623.1.1.2.2023.2320   1.3.6.1.4.1.25623.1.1.2.2023.2706   1.3.6.1.4.1.25623.1.0.893331   1.3.6.1.4.1.25623.1.1.2.2024.1293   1.3.6.1.4.1.25623.1.1.2.2023.2664   1.3.6.1.4.1.25623.1.1.9.2023.51706102881013   1.3.6.1.4.1.25623.1.1.2.2023.2340   1.3.6.1.4.1.25623.1.1.2.2023.2531   1.3.6.1.4.1.25623.1.1.4.2023.1767.1   1.3.6.1.4.1.25623.1.1.2.2023.2491   1.3.6.1.4.1.25623.1.1.2.2023.2740   1.3.6.1.4.1.25623.1.0.827285   1.3.6.1.4.1.25623.1.1.4.2023.0737.1   1.3.6.1.4.1.25623.1.1.2.2023.1809   1.3.6.1.4.1.25623.1.1.2.2024.1700   1.3.6.1.4.1.25623.1.1.4.2023.0837.1   1.3.6.1.4.1.25623.1.0.827305   1.3.6.1.4.1.25623.1.0.827210   1.3.6.1.4.1.25623.1.1.2.2023.2518   1.3.6.1.4.1.25623.1.1.2.2023.2771  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-23931
https://github.com/pyca/cryptography/pull/8230/commits/94a50a9731f35405f0357fa5f3b177d46a726ab3
https://github.com/pyca/cryptography/pull/8230/commits/94a50a9731f35405f0357fa5f3b177d46a726ab3
https://github.com/pyca/cryptography/security/advisories/GHSA-w7pp-m8wf-vj6r
https://github.com/pyca/cryptography/security/advisories/GHSA-w7pp-m8wf-vj6r




© 1998-2025 E-Soft Inc. All rights reserved.