Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python2-cryptoUpgrade python-crypto-debuginfo | Jun 26, 2024 | Feb 15, 2017 |
| Amazon_linux | — | Upgrade python-crypto | Mar 7, 2017 | Feb 15, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 15, 2017 |
| Debian | — | Upgrade python-crypto | Mar 31, 2017 | Jan 1, 2017 |
| Gentoo Linux | — | Upgrade dev-python/pycrypto. | Oct 30, 2017 | Feb 15, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade python-crypto | Dec 4, 2019 | Feb 15, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade python-crypto | Jun 28, 2018 | Feb 15, 2017 |
| Suse | — | Upgrade python3-pycryptoUpgrade python-paramikoUpgrade python-pycryptoUpgrade python2-pycrypto | Aug 9, 2024 | Feb 15, 2017 |
| Ubuntu | — | Upgrade python3-cryptoUpgrade python-crypto | Feb 17, 2017 | Feb 15, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 15, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub