QID 981123
QID 981123: Python (pip) Security Update for pycrypto (GHSA-cq27-v7xp-c356)
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cq27-v7xp-c356 for updates pertaining to this vulnerability.
Vendor References
- GHSA-cq27-v7xp-c356 -
github.com/advisories/GHSA-cq27-v7xp-c356
CVEs related to QID 981123
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cq27-v7xp-c356 | pycrypto |
|