Advisories for Pypi/PyOpenSSL package

2018

Use After Free

Python Cryptographic Authority pyopenssl conatains a Use After Free vulnerability in Xobject handling that can lead to possible denial of service or remote code execution.

2013

Improper Input Validation

The X509Extension in pyOpenSSL does not properly handle a \0 character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.