VDB

GCVE-110-MAGEIA-2013-319

GCVE-110-MAGEIA-2013-319
Advisory Published
Vulnetix · Advisory published October 25, 2013
Updated python-pycrypto package fixes security vulnerability: In PyCrypto before v2.6.1, the Crypto.Random pseudo-random number generator (PRNG) exhibits a race condition that may cause it to generate the same 'random' output in multiple processes that are forked from each other. Depending on the application, this could reveal sensitive information or cryptographic keys to remote attackers (CVE-2013-1445).

Affected Products

VendorProductVersionsPlatforms
Mageiapython-pycrypto0 (affected), 2.3-2.2.mga2 (unaffected)
Mageiapython-pycrypto2.6-2.1.mga3 (unaffected), 0 (affected)

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›