—
PYSEC-2013-29
Quick fix
PYSEC-2013-29 — pycrypto: upgrade to the fixed version with the command below.
pip install --upgrade 'pycrypto>=19dcf7b15d61b7dc1a125a367151de40df6ef175'Details
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is created and accesses the PRNG within the same rate-limit period as another process.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/pycrypto
Introduced in:
0Fixed in: 19dcf7b15d61b7dc1a125a367151de40df6ef175Fix
pip install --upgrade 'pycrypto>=19dcf7b15d61b7dc1a125a367151de40df6ef175'