Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-7459

Опубликовано: 15 фев. 2017
Источник: debian

Описание

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-cryptofixed2.6.1-7package
python-cryptofixed2.6.1-5+deb8u1jessiepackage

Примечания

  • https://github.com/dlitz/pycrypto/issues/176

  • Fixed by: https://github.com/dlitz/pycrypto/commit/8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4

  • All users of pycrypto's AES module in Debian that allow the mode

  • of operation to be specified from outside check for ECB explicitly

  • and create the objects without specifying an IV.

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

CVSS3: 9.8
redhat
около 10 лет назад

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

CVSS3: 9.8
nvd
почти 9 лет назад

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

suse-cvrf
около 9 лет назад

Security update for python-pycrypto

suse-cvrf
больше 8 лет назад

Security update for python-pycrypto