PublicDateAtUSN: 2017-02-15 Candidate: CVE-2013-7459 PublicDate: 2017-02-15 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7459 https://github.com/dlitz/pycrypto/issues/176 https://pony7.fr/ctf:public:32c3:cryptmsg https://ubuntu.com/security/notices/USN-3199-2 https://ubuntu.com/security/notices/USN-3199-1 https://ubuntu.com/security/notices/USN-3199-3 Description: Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=849495 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_python-crypto: upstream_python-crypto: released (2.6.1-7) precise_python-crypto: ignored (reached end-of-life) precise/esm_python-crypto: released (2.4.1-1ubuntu0.2) trusty_python-crypto: released (2.6.1-4ubuntu0.1) trusty/esm_python-crypto: released (2.6.1-4ubuntu0.1) vivid/stable-phone-overlay_python-crypto: pending (2.6.1-5ubuntu0.1) vivid/ubuntu-core_python-crypto: released (2.6.1-5ubuntu0.1) xenial_python-crypto: released (2.6.1-6ubuntu0.16.04.1) esm-infra/xenial_python-crypto: released (2.6.1-6ubuntu0.16.04.1) yakkety_python-crypto: released (2.6.1-6ubuntu0.16.10.2) zesty_python-crypto: not-affected (2.6.1-7) devel_python-crypto: not-affected (2.6.1-7)