GHSA-hgg3-g7gr-66r7
Dashboard / Vulnerabilities / GHSA-hgg3-g7gr-66r7
GHSA-hgg3-g7gr-66r7
Summary: PyCryptodome integer overflow vulnerability
Details: PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-15560, https://github.com/Legrandin/pycryptodome/issues/198, https://github.com/Legrandin/pycryptodome, https://github.com/advisories/GHSA-hgg3-g7gr-66r7, https://github.com/pypa/advisory-database/tree/main/vulns/pycryptodome/PYSEC-2018-21.yaml, https://whitehatck01.blogspot.com/2018/08/integer-overflow-vulnerability-in.html
Affected packages
Package
Name: pycryptodome
Purl: pkg:pypi/pycryptodome
Affected ranges
Type: ECOSYSTEM
Events:
