The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cryptography | Cryptography.io | 40.0.0 (including) | 41.0.2 (excluding) |
Python-cryptography | Ubuntu | bionic | * |
Python-cryptography | Ubuntu | trusty | * |
Python-cryptography | Ubuntu | xenial | * |