QID 981045
QID 981045: Python (pip) Security Update for pycryptodome (GHSA-hgg3-g7gr-66r7)
PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hgg3-g7gr-66r7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-hgg3-g7gr-66r7 -
github.com/advisories/GHSA-hgg3-g7gr-66r7
CVEs related to QID 981045
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hgg3-g7gr-66r7 | pycryptodome |
|