9.8
CVSSv3

CVE-2013-7459

Published: 15/02/2017 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote malicious users to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

Vulnerable Product Search on Vulmon Subscribe to Product

dlitz pycrypto

fedoraproject fedora 25

fedoraproject fedora 24

Vendor Advisories

Debian Bug report logs - #849495 python-crypto: CVE-2013-7459 Package: src:python-crypto; Maintainer for src:python-crypto is Sebastian Ramacher <sramacher@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 27 Dec 2016 21:51:02 UTC Severity: grave Tags: patch, security, upstream Found in v ...
USN-3199-1 introduced a regression in the Python Cryptography Toolkit which caused programs which relied on the original behavior to fail ...
Programs using the Python Cryptography Toolkit could be made to crash or run programs if they receive specially crafted network traffic or other input ...
Programs using the Python Cryptography Toolkit could be made to crash or run programs if they receive specially crafted network traffic or other input ...
A heap-buffer overflow vulnerability was discovered in cryptopp This vulnerability can be used to remotely gain access to shell ...