CVE-2013-7459: Dlitz Pycrypto

Critical severity, CVSS 9.8. EPSS: 9.6% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

Affected products

  • Dlitz Pycrypto: up to and including 2.6.1
  • Fedoraproject Fedora: version 24 only; version 25 only

Published 2017-02-15. Last modified 2026-06-17.