CVE-2013-7459Improper Restriction of Operations within the Bounds of a Memory Buffer in Pycrypto

Severity
9.8CRITICALNVD
EPSS
14.5%
top 5.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateJul 8

Description

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

PyPIdlitz/pycrypto< 8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4+1
NVDdlitz/pycrypto2.6.1
Palo Altopaloalto/pan-os

Also affects: Fedora 24, 25

Patches

🔴Vulnerability Details

4
OSV
Buffer Overflow in pycrypto2018-12-14
GHSA
Buffer Overflow in pycrypto2018-12-14
CVEList
CVE-2013-7459: Heap-based buffer overflow in the ALGnew function in block_templace2017-02-15
OSV
CVE-2013-7459: Heap-based buffer overflow in the ALGnew function in block_templace2017-02-15

📋Vendor Advisories

5
Palo Alto
PAN2020-07-08
Ubuntu
Python Crypto vulnerability2017-08-28
Ubuntu
Python Crypto regression2017-02-17
Ubuntu
Python Crypto vulnerability2017-02-16
Red Hat
pycrypto: Heap-buffer overflow in ALGobject structure2015-12-15

💬Community

1
Bugzilla
CVE-2013-7459 pycrypto: Heap-buffer overflow in ALGobject structure2017-01-03
CVE-2013-7459 — Dlitz Pycrypto vulnerability | cvebase