Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Gentoo GLSA 200903-11 Normal: PyCrypto Arbitrary Code Execution

gentoo
Calendar Grey March 9, 2009
Dist Gentoo Esm H88
A Gentoo GLSA outlines vulnerabilities within libcurl that could permit remote code execution, highlighting the necessity for immediate updates to safeguard system integrity.
A buffer overflow in PyCrypto might lead to the execution of arbitrary code when decrypting using ARC2.

Summary

Gentoo Linux Security Advisory GLSA 200903-11 https://security.gentoo.org/ Severity: Normal Title: PyCrypto: Execution of arbitrary code Date: March 09, 2009 Bugs: #258049 ID: 200903-11

Synopsis ======= A buffer overflow in PyCrypto might lead to the execution of arbitrary code when decrypting using ARC2.
Background ========= PyCrypto is the Python Cryptography Toolkit.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-python/pycrypto < 2.0.1-r8 >= 2.0.1-r8
========== Mike Wiacek of the Google Security Team reported a buffer overflow in the ARC2 module when processing a large ARC2 key length.
Impact ===== A remote attacker could entice a user or automated syst...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Your message here