Lucene search

K
osvGoogleOSV:GHSA-X377-F64P-HF5J
HistoryMay 17, 2022 - 4:59 a.m.

PyCrypto does not properly reseed PRNG before allowing access

2022-05-1704:59:18
Google
osv.dev
5

9.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.8%

The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is created and accesses the PRNG within the same rate-limit period as another process.

9.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.8%