HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2017-03-27 17:59
Updated : 2025-04-20 01:37
NVD link : CVE-2016-9243
Mitre link : CVE-2016-9243
CVE.ORG link : CVE-2016-9243
JSON object : View
Products Affected
fedoraproject
- fedora
canonical
- ubuntu_linux
cryptography.io
- cryptography
CWE