GCVE-VVD-MAGEIA-2017-32
Advisory Published
Vulnetix · Advisory published July 25, 2017
This is a security fix for a possible Buffer overflow. AES.new with invalid parameter crashes python. The IV parameter is currently ignored when initializing a cipher in ECB or CTR mode. There was a bug in pycrypto which could be exploited to get a shell.

Affected Products

VendorProductVersionsPlatforms
Mageiapython-pycrypto0 (affected), 2.6.1-6.1.mga5 (unaffected), 0 (affected), 2.6.1-6.1.mga5 (unaffected)
Mageiamageiawelcome0 (affected), 1.13-1.mga6 (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.