CVE-2013-7459

critical
Published 2017-02-15 · Modified 2023-11-08
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/dlitz/pycrypto/issues/176

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/dlitz/pycrypto/commit/8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2013-7459.html

OS impact

OSVersionStatusFixed in
suse slesaffected
fedora fedora24affected
fedora fedora25affected

Package impact

EcosystemPackageVulnerableFixed
python PyPIpycrypto<=2.6.1
python PyPIpycrypto<8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d48dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4

Application impact

VendorProductVersionsFixed
dlitzpycrypto{"endIncluding":"2.6.1"}

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.