Your submission was sent successfully! Close

CVE-2013-7459

Published: 15 February 2017

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

Priority

Medium

CVSS 3 base score: 9.8

Status

Package Release Status
python-crypto
Launchpad, Ubuntu, Debian
Upstream
Released (2.6.1-7)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (2.6.1-6ubuntu0.16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (2.6.1-4ubuntu0.1)