Buffer overflow in Fedora - CVE-2013-7459

 

Buffer overflow in Fedora - CVE-2013-7459

Published: February 15, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU39653
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-7459
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.


Affected software

Fedora
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux
Opensuse
IBM Cloud Pak System
IBM Integrated Analytics System
Cloud Pak for Security (CP4S)
python-crypto
IBM Watson Machine Learning Accelerator
IBM Netezza Analytics

How to mitigate CVE-2013-7459

Install update from vendor's website.

IBM Cloud Pak System - update to 2.3.3.6
IBM Integrated Analytics System - update to 1.0.28.1
Cloud Pak for Security (CP4S) - update to 1.10.12.0
python-crypto - addressed in versions 2.0.1-6.el5, 2.6.1-13.el7, 2.6.1-13.fc24, 2.6.1-13.fc25
IBM Watson Machine Learning Accelerator - update to 4.0
IBM Netezza Analytics - update to 11.2.29

External References

Related Security Bulletins