Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Ubuntu 12.04 ESM: USN-3199-3 Critical: Python Crypto Heap Overflow

Ubuntu Large Esm H500
Programs using the Python Cryptography Toolkit could be made to crash or run programs if they receive specially crafted network traffic or other input.
=========================================================================Ubuntu Security Notice USN-3199-3
August 28, 2017

python-crypto vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Programs using the Python Cryptography Toolkit could be made to
crash or run programs if they receive specially crafted network
traffic or other input.

Software Description:
- python-crypto: cryptographic algorithms and protocols for Python

Details:

USN-3199-1 fixed a vulnerability in Python Crypto. This update
provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that the ALGnew function in block_templace.c in the
 Python Cryptography Toolkit contained a heap-based buffer overflow
 vulnerability. A remote attacker could use this flaw to execute
 arbitrary code by using a crafted initialization vector parameter.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  python-crypto                   2.4.1-1ubuntu0.2
  python3-crypto                  2.4.1-1ubuntu0.2

In general, a standard system update will make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-3199-3
  https://ubuntu.com/security/notices/USN-3199-1
  CVE-2013-7459

Ubuntu 12.04 ESM: USN-3199-3 Critical: Python Crypto Heap Overflow

ubuntu
Calendar Grey August 28, 2017
Dist Ubuntu Esm H88
Comprehensive guidance on the Python cryptography vulnerability patch for Ubuntu, focusing on severe remote code execution threats.
Programs using the Python Cryptography Toolkit could be made to crash or run programs if they receive specially crafted network traffic or other input.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM:   python-crypto                   2.4.1-1ubuntu0.2   python3-crypto                  2.4.1-1ubuntu0.2 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3199-3

  https://ubuntu.com/security/notices/USN-3199-1

  CVE-2013-7459

Severity
critical
Lowest
Low
Medium
High
Critical

August 28, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here