← Back

CVE-2013-1445

nvd nist
Published: Oct 26, 2013Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is created and accesses the PRNG within the same rate-limit period as another process.

Affected (12)

Products: Dlitz: Pycrypto
1 product
Pycrypto
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Dlitz
Up to 2.6
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 2.0.1
Version 2.0
Version 2.1.0
Version 2.2
Version 2.3
Version 2.4.1
Version 2.4
Version 2.5

Related CWEs

References (6)

Source: security@debian.org
ExploitPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch

Timeline

No history available yet.