Junglewise Threat Intelligence

CVE-2013-7459: PYSEC-2017-94 - Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers

CVE-2013-7459 · Severity: low · CVSS 3 · Published 2017-02-15

Technologies: pycrypto (PyPI). Vendors: PyPI.

Executive brief

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

Affected products

  • PyPI pycrypto

Related threats