Buffer overflow in Fedora - CVE-2013-7459
Published: February 15, 2017 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
Affected software
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Opensuse
IBM Cloud Pak System
IBM Integrated Analytics System
Cloud Pak for Security (CP4S)
python-crypto
IBM Watson Machine Learning Accelerator
IBM Netezza Analytics
How to mitigate CVE-2013-7459
IBM Integrated Analytics System - update to 1.0.28.1
Cloud Pak for Security (CP4S) - update to 1.10.12.0
python-crypto - addressed in versions 2.0.1-6.el5, 2.6.1-13.el7, 2.6.1-13.fc24, 2.6.1-13.fc25
IBM Watson Machine Learning Accelerator - update to 4.0
IBM Netezza Analytics - update to 11.2.29
External References
- http://www.openwall.com/lists/oss-security/2016/12/27/8
- http://www.securityfocus.com/bid/95122
- https://bugzilla.redhat.com/show_bug.cgi?id=1409754
- https://github.com/dlitz/pycrypto/commit/8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4
- https://github.com/dlitz/pycrypto/issues/176
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C6BWNADPLKDBBQBUT3P75W7HAJCE7M3B/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJ37R2YLX56YZABFNAOWV4VTHTGYREAE/
- https://pony7.fr/ctf:public:32c3:cryptmsg
- https://security.gentoo.org/glsa/201702-14
Related Security Bulletins
- Buffer overflow in Fedoraproject Fedora
- SUSE Linux update for python-pycrypto
- OpenSUSE Linux update for python-pycrypto
- Arch Linux update for python-crypto
- Arch Linux update for python2-crypto
- Amazon Linux AMI update for python-crypto
- Gentoo update for PyCrypto
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Integrated Analytics System
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Fedora EPEL 5 update for python-crypto
- Fedora EPEL 7 update for python-crypto
- Fedora 25 update for python-crypto
- Fedora 24 update for python-crypto
- Multiple vulnerabilities in IBM Netezza Analytics - NPS