The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is created and accesses the PRNG within the same rate-limit period as another process.
CVSS Details
- CVSS 3.1 Base Score: 3.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade py26-pycryptoUpgrade py33-pycryptoUpgrade py27-pycryptoUpgrade py31-pycryptoUpgrade py32-pycrypto | Dec 10, 2025 | Oct 19, 2013 |
| Suse | — | Upgrade python-pycryptoUpgrade python2-pycryptoUpgrade python3-pycrypto | Aug 9, 2024 | Oct 26, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub