{"schema_version":"1.7.5","id":"CVE-2020-36242","published":"2021-02-07T20:15:12.090Z","modified":"2026-08-07T10:12:00.024016348Z","aliases":["GHSA-rhm9-p9w5-fwm7","PYSEC-2021-63"],"related":["SUSE-FU-2022:0444-1","SUSE-FU-2022:0445-1","SUSE-RU-2022:4567-1","SUSE-SU-2021:0594-1","SUSE-SU-2021:0668-1","SUSE-SU-2021:0669-1","SUSE-SU-2021:0675-1","SUSE-SU-2021:0696-1","SUSE-SU-2023:0604-1","SUSE-SU-2023:1838-1","SUSE-SU-2023:2783-1","SUSE-SU-2023:2783-2","openSUSE-SU-2021:0349-1","openSUSE-SU-2024:11223-1","openSUSE-SU-2024:13819-1","openSUSE-SU-2026:11468-1"],"details":"In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pyca/cryptography","events":[{"introduced":"0"},{"fixed":"82b6ce28389f0a317bc55ba2091a74b346db7cae"}],"database_specific":{"cpe":"cpe:2.3:a:cryptography.io:cryptography:*:*:*:*:*:python:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.3.2"}],"source":"CPE_RANGE"}}],"versions":["3.3.1","3.3","3.2","3.1","3.0","2.9","2.8","2.7","2.6.1","2.6","2.5","2.4.1","2.4","2.3","2.2","2.1","2.0","1.9","1.8","1.7","1.6","1.5","1.4","1.3","1.2","1.1","1.0","0.9","0.8","0.7","0.6","0.5.1","0.5","0.4","0.3","0.2","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36242.json"}}],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L7RGQLK4J5ZQFRLKCHVVG6BKZTUQMG7E/"},{"type":"ADVISORY","url":"https://github.com/pyca/cryptography/blob/master/CHANGELOG.rst"},{"type":"FIX","url":"https://github.com/pyca/cryptography/compare/3.3.1...3.3.2"},{"type":"FIX","url":"https://github.com/pyca/cryptography/issues/5615"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"33"},{"last_affected":"33"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"},{"cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.10.0"},{"last_affected":"1.10.0"}],"source":"CPE_STRING","vendor_product":"oracle:communications_cloud_native_core_network_function_cloud_native_environment"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}