CVE-2013-1895
Publication date 28 January 2020
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| python-bcrypt | 14.04 LTS trusty | Not in release |
Notes
Patch details
| Package | Patch details |
|---|---|
| python-bcrypt |
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | High |
| Availability impact | None |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |