#VU42419 Cryptographic issues in PyCrypto - CVE-2013-1445
Published: October 26, 2013 / Updated: August 10, 2020
PyCrypto
GNU
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is created and accesses the PRNG within the same rate-limit period as another process.