CVE-2013-1445: Dlitz Pycrypto
Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is created and accesses the PRNG within the same rate-limit period as another process.
Affected products
- Dlitz Pycrypto: up to and including 2.6; version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 2.0 only; version 2.0.1 only; …
Published 2013-10-26. Last modified 2026-06-16.