Arbitrary Code Execution Affecting pycrypto package, versions [,2.7a1]
Threat Intelligence
EPSS
1.43% (87th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-PYCRYPTO-40249
- published 1 Aug 2017
- disclosed 15 Dec 2015
- credit Unknown
Introduced: 15 Dec 2015
CVE-2013-7459 Open this link in a new tabHow to fix?
The fix is merged to the master branch but not yet published
Overview
pycrypto
is a Cryptographic modules for Python.
Affected versions of this package are vulnerable to Arbitrary Code Execution. Heap-based buffer overflow in the ALGnew function in block_templace.c
in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py
.
CVSS Scores
version 3.1