VDB
Sign up
—

PYSEC-2017-94

Quick fix

PYSEC-2017-94 — pycrypto: upgrade to the fixed version with the command below.

pip install --upgrade 'pycrypto>=8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4'

Details

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pycrypto
Introduced in: 0Fixed in: 8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4
Fixpip install --upgrade 'pycrypto>=8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4'

References