CVE-2009-0544

Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.
References
Link Resource
http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=d1c4875e1f220652fe7ff8358f56dee3b2aba31b
http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=fd73731dfad451a81056fbb01e09aa78ab82eb5d
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://secunia.com/advisories/34199
http://secunia.com/advisories/35065
http://www.gentoo.org/security/en/glsa/glsa-200903-11.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:049
http://www.mandriva.com/security/advisories?name=MDVSA-2009:050
http://www.openwall.com/lists/oss-security/2009/02/07/1
http://www.openwall.com/lists/oss-security/2009/02/12/5
http://www.securityfocus.com/bid/33674 Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/48617
http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=d1c4875e1f220652fe7ff8358f56dee3b2aba31b
http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=fd73731dfad451a81056fbb01e09aa78ab82eb5d
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://secunia.com/advisories/34199
http://secunia.com/advisories/35065
http://www.gentoo.org/security/en/glsa/glsa-200903-11.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:049
http://www.mandriva.com/security/advisories?name=MDVSA-2009:050
http://www.openwall.com/lists/oss-security/2009/02/07/1
http://www.openwall.com/lists/oss-security/2009/02/12/5
http://www.securityfocus.com/bid/33674 Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/48617
Configurations

Configuration 1 (hide)

cpe:2.3:a:pycrypto:arc2:2.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:00

Type Values Removed Values Added
References () http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=d1c4875e1f220652fe7ff8358f56dee3b2aba31b - () http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=d1c4875e1f220652fe7ff8358f56dee3b2aba31b -
References () http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=fd73731dfad451a81056fbb01e09aa78ab82eb5d - () http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=fd73731dfad451a81056fbb01e09aa78ab82eb5d -
References () http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html - () http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html -
References () http://secunia.com/advisories/34199 - () http://secunia.com/advisories/34199 -
References () http://secunia.com/advisories/35065 - () http://secunia.com/advisories/35065 -
References () http://www.gentoo.org/security/en/glsa/glsa-200903-11.xml - () http://www.gentoo.org/security/en/glsa/glsa-200903-11.xml -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2009:049 - () http://www.mandriva.com/security/advisories?name=MDVSA-2009:049 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2009:050 - () http://www.mandriva.com/security/advisories?name=MDVSA-2009:050 -
References () http://www.openwall.com/lists/oss-security/2009/02/07/1 - () http://www.openwall.com/lists/oss-security/2009/02/07/1 -
References () http://www.openwall.com/lists/oss-security/2009/02/12/5 - () http://www.openwall.com/lists/oss-security/2009/02/12/5 -
References () http://www.securityfocus.com/bid/33674 - Exploit () http://www.securityfocus.com/bid/33674 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/48617 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/48617 -

07 Nov 2023, 02:03

Type Values Removed Values Added
References
  • {'url': 'http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=fd73731dfad451a81056fbb01e09aa78ab82eb5d', 'name': 'http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=fd73731dfad451a81056fbb01e09aa78ab82eb5d', 'tags': ['Exploit'], 'refsource': 'CONFIRM'}
  • {'url': 'http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=d1c4875e1f220652fe7ff8358f56dee3b2aba31b', 'name': 'http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=d1c4875e1f220652fe7ff8358f56dee3b2aba31b', 'tags': ['Exploit'], 'refsource': 'CONFIRM'}
  • () http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=fd73731dfad451a81056fbb01e09aa78ab82eb5d -
  • () http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git%3Ba=commitdiff%3Bh=d1c4875e1f220652fe7ff8358f56dee3b2aba31b -

Information

Published : 2009-02-12 17:30

Updated : 2024-11-21 01:00


NVD link : CVE-2009-0544

Mitre link : CVE-2009-0544

CVE.ORG link : CVE-2009-0544


JSON object : View

Products Affected

pycrypto

  • arc2
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer