Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3175
HistoryDec 27, 2016 - 3:19 a.m.

Arbitrary Remote Code Execution Via Buffer Overflow

2016-12-2703:19:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.014

Percentile

86.6%

pycrypto is vulnerable to remote code execution (RCE) via heap buffer overflow attacks. There is a heap buffer overflow on ALGobject.IV in block_templace.c, where attackers can write as many bytes as they want on part of the heap, and exploit it to control the execution flow to execute shell commands.