CVE-2016-9243
27.03.2017, 17:59
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.Enginsight
Vendor | Product | Version |
---|---|---|
cryptography.io | cryptography | 𝑥 ≤ 1.5.2 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 16.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References