MGASA-2013-0319
Dashboard / Vulnerabilities / MGASA-2013-0319
Summary: Updated python-pycrypto packages fix CVE-2013-1445
Details: Updated python-pycrypto package fixes security vulnerability: In PyCrypto before v2.6.1, the Crypto.Random pseudo-random number generator (PRNG) exhibits a race condition that may cause it to generate the same 'random' output in multiple processes that are forked from each other. Depending on the application, this could reveal sensitive information or cryptographic keys to remote attackers (CVE-2013-1445).
References: https://advisories.mageia.org/MGASA-2013-0319.html, http://lists.dlitz.net/pipermail/pycrypto/2013q4/000702.html, https://bugs.mageia.org/show_bug.cgi?id=11491
Affected packages
Package
Name: python-pycrypto
Purl: pkg:rpm/mageia/python-pycrypto?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
