Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
References
Configurations
History
21 Nov 2024, 02:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2016/12/27/8 - Mailing List, Third Party Advisory | |
References | () http://www.securityfocus.com/bid/95122 - Third Party Advisory, VDB Entry | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1409754 - Issue Tracking, Third Party Advisory, VDB Entry | |
References | () https://github.com/dlitz/pycrypto/commit/8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4 - Patch | |
References | () https://github.com/dlitz/pycrypto/issues/176 - Patch, Vendor Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C6BWNADPLKDBBQBUT3P75W7HAJCE7M3B/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJ37R2YLX56YZABFNAOWV4VTHTGYREAE/ - | |
References | () https://pony7.fr/ctf:public:32c3:cryptmsg - Exploit, Technical Description, Third Party Advisory | |
References | () https://security.gentoo.org/glsa/201702-14 - |
Information
Published : 2017-02-15 15:59
Updated : 2024-11-21 02:01
NVD link : CVE-2013-7459
Mitre link : CVE-2013-7459
CVE.ORG link : CVE-2013-7459
JSON object : View
Products Affected
fedoraproject
- fedora
dlitz
- pycrypto
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer