CVE-2013-1895
Summary
| CVE | CVE-2013-1895 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-28 15:15:00 UTC |
| Updated | 2020-02-04 16:49:00 UTC |
| Description | The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - CVE-2013-1895 py-bcrypt 0.2 concurrency vulnerability (auth bypass) |
MISC |
www.openwall.com |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 18 Update: py-bcrypt-0.3-1.fc18 |
MISC |
lists.fedoraproject.org |
Third Party Advisory, Tool Signature |
| Python 'py-bcrypt' Module CVE-2013-1895 Authentication Bypass Vulnerability |
MISC |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [SECURITY] Fedora 17 Update: py-bcrypt-0.3-1.fc17 |
MISC |
lists.fedoraproject.org |
Third Party Advisory |
| IBM X-Force Exchange |
MISC |
exchange.xforce.ibmcloud.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980442 Python (pip) Security Update for py-bcrypt (GHSA-r838-q6jp-58xx)