Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question: What are the fix patches for CVE-2023-52323? #796

Open
xiaoge1001 opened this issue Jan 18, 2024 · 5 comments
Open

Question: What are the fix patches for CVE-2023-52323? #796

xiaoge1001 opened this issue Jan 18, 2024 · 5 comments

Comments

@xiaoge1001
Copy link

xiaoge1001 commented Jan 18, 2024

I found 26 commits between versions 3.19.0 and 3.19.1. Which ones fix CVE-2023-52323?

My analysis should be the following commit:
afb5e27
519e7ae
0deea1b

In addition, does CVE-2023-52323 provide other information such as POC or issue? The information available is very limited.
https://nvd.nist.gov/vuln/detail/CVE-2023-52323
https://github.com/Legrandin/pycryptodome/blob/master/Changelog.rst#3191-28-december-2023
https://www.pycryptodome.org/src/changelog#december-2023

We look forward to your reply. Thanks.

@xiaoge1001
Copy link
Author

This advisories is associated with the following patch:
0deea1b

@xiaoge1001
Copy link
Author

https://groups.google.com/g/linux.debian.bugs.dist/c/ibzqvtwhi8M
It is also associated with the patch 0deea1b

@eslerm
Copy link

eslerm commented Jan 23, 2024

[ removed, my mistake ]

@jiajia123-wind
Copy link

Hi @Legrandin,

I am facing a similar issue with WRLinux LTS23, which requires a patch on pycryptodome_3.17 to resolve CVE-2023-52323. Could you kindly provide the specific commit for this fix?

Thank you for your assistance!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants