CVE-2018-15560

PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pycryptodome:pycryptodome:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:51

Type Values Removed Values Added
References () https://github.com/Legrandin/pycryptodome/issues/198 - Exploit, Third Party Advisory () https://github.com/Legrandin/pycryptodome/issues/198 - Exploit, Third Party Advisory
References () https://whitehatck01.blogspot.com/2018/08/integer-overflow-vulnerability-in.html - Exploit, Third Party Advisory () https://whitehatck01.blogspot.com/2018/08/integer-overflow-vulnerability-in.html - Exploit, Third Party Advisory

Information

Published : 2018-08-20 00:29

Updated : 2024-11-21 03:51


NVD link : CVE-2018-15560

Mitre link : CVE-2018-15560

CVE.ORG link : CVE-2018-15560


JSON object : View

Products Affected

pycryptodome

  • pycryptodome
CWE
CWE-190

Integer Overflow or Wraparound