CVE-2013-7459
published 2017-02-15CVE-2013-7459: Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute…
PriorityP354critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
9.50%
94.9th percentile
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlitz | pycrypto | <= 2.6.1 | — |
| dlitz | pycrypto | >= 0 < 8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4 | 8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4 |
| dlitz | pycrypto | 0 – 2.6.1 | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN
vendor_paloalto·2020-07-08·CVSS 9.8
CVE-2013-7459 [CRITICAL] PAN
PAN
The Palo Alto Networks Product Security Assurance team has evaluated and determined that these third-party or open source vulnerabilities do not have any security impact on PAN-OS or that the scenarios required for successful
CVEs: CVE-2013-7459, CVE-2018-1120, CVE-2018-1121, CVE-2018-1122, CVE-2018-1123, CVE-2018-1124, CVE-2018-16402, CVE-2020-11022, CVE-2020-11023, CVE-2020-11896, CVE-2020-11897, CVE-2020-11898, CVE-2020-11899, CVE-2020-11900, CVE-2020-11901, CVE-2020-11902, CVE-2020-11903, CVE-2020-11904, CVE-2020-11905, CVE-2020-11906, CVE-2020-11907, CVE-2020-11908, CVE-2020-11909, CVE-2020-11910, CVE-2020-11911, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914
Affected products: PAN-OS
Ubuntu
Python Crypto vulnerability
vendor_ubuntu·2017-08-28
CVE-2013-7459 Python Crypto vulnerability
Title: Python Crypto vulnerability
Summary: Programs using the Python Cryptography Toolkit could be made to
crash or run programs if they receive specially crafted network
traffic or other input.
USN-3199-1 fixed a vulnerability in Python Crypto. This update
provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that the ALGnew function in block_templace.c in the Python
Cryptography Toolkit contained a heap-based buffer overflow vulnerability.
A remote attacker could use this flaw to execute arbitrary code by using
a crafted initialization vector parameter.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python Crypto regression
vendor_ubuntu·2017-02-17
CVE-2013-7459 Python Crypto regression
Title: Python Crypto regression
Summary: USN-3199-1 introduced a regression in the Python Cryptography Toolkit which
caused programs which relied on the original behavior to fail.
USN-3199-1 fixed a vulnerability in the Python Cryptography Toolkit.
Unfortunately, various programs depended on the original behavior of the Python
Cryptography Toolkit which was altered when fixing the vulnerability. This
update retains the fix for the vulnerability but issues a warning rather than
throwing an exception. Code which produces this warning should be updated
because future versions of the Python Cryptography Toolkit re-introduce the
exception.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the ALGnew function in block_template.c in the Python
Cryptography
Ubuntu
Python Crypto vulnerability
vendor_ubuntu·2017-02-16
CVE-2013-7459 Python Crypto vulnerability
Title: Python Crypto vulnerability
Summary: Programs using the Python Cryptography Toolkit could be made to crash or run
programs if they receive specially crafted network traffic or other input.
It was discovered that the ALGnew function in block_templace.c in the Python
Cryptography Toolkit contained a heap-based buffer overflow vulnerability.
A remote attacker could use this flaw to execute arbitrary code by using
a crafted initialization vector parameter.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pycrypto: Heap-buffer overflow in ALGobject structure
vendor_redhat·2015-12-15·CVSS 9.8
CVE-2013-7459 [CRITICAL] CWE-122 pycrypto: Heap-buffer overflow in ALGobject structure
pycrypto: Heap-buffer overflow in ALGobject structure
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
Package: python-crypto (Red Hat Ceph Storage 1.3) - Will not fix
Package: python-crypto (Red Hat Ceph Storage 2) - Will not fix
Package: python-crypto (Red Hat Enterprise Linux 6) - Not affected
Package: python-crypto (Red Hat Enterprise Linux 7) - Not affected
Package: python-crypto (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Will not fix
Package: python-crypto (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Package: python-crypto (Red Hat Enterprise Virtualization 3) - Not
OSV
Buffer Overflow in pycrypto
osv·2018-12-14
CVE-2013-7459 [CRITICAL] Buffer Overflow in pycrypto
Buffer Overflow in pycrypto
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
GHSA
Buffer Overflow in pycrypto
ghsa·2018-12-14
CVE-2013-7459 [CRITICAL] CWE-119 Buffer Overflow in pycrypto
Buffer Overflow in pycrypto
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
OSV
CVE-2013-7459: Heap-based buffer overflow in the ALGnew function in block_templace
osv·2017-02-15
CVE-2013-7459 CVE-2013-7459: Heap-based buffer overflow in the ALGnew function in block_templace
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2016/12/27/8http://www.securityfocus.com/bid/95122https://bugzilla.redhat.com/show_bug.cgi?id=1409754https://github.com/dlitz/pycrypto/commit/8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4https://github.com/dlitz/pycrypto/issues/176https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C6BWNADPLKDBBQBUT3P75W7HAJCE7M3B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJ37R2YLX56YZABFNAOWV4VTHTGYREAE/https://pony7.fr/ctf:public:32c3:cryptmsghttps://security.gentoo.org/glsa/201702-14http://www.openwall.com/lists/oss-security/2016/12/27/8http://www.securityfocus.com/bid/95122https://bugzilla.redhat.com/show_bug.cgi?id=1409754https://github.com/dlitz/pycrypto/commit/8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4https://github.com/dlitz/pycrypto/issues/176https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C6BWNADPLKDBBQBUT3P75W7HAJCE7M3B/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJ37R2YLX56YZABFNAOWV4VTHTGYREAE/https://pony7.fr/ctf:public:32c3:cryptmsghttps://security.gentoo.org/glsa/201702-14
2017-02-15
Published