Vulnerability Name:

CVE-2009-0544 (CCN-48617)

Assigned:2009-02-06
Published:2009-02-06
Updated:2017-08-08
Summary:Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.6 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2009-0544

Source: CCN
Type: Python Cryptography Toolkit GIT Repository
gitweb2.dlitz.net Git - crypto/pycrypto-2.x.git/commitdiff

Source: CONFIRM
Type: Exploit
http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=d1c4875e1f220652fe7ff8358f56dee3b2aba31b

Source: CONFIRM
Type: Exploit
http://gitweb2.dlitz.net/?p=crypto/pycrypto-2.x.git;a=commitdiff;h=fd73731dfad451a81056fbb01e09aa78ab82eb5d

Source: SUSE
Type: UNKNOWN
SUSE-SR:2009:010

Source: SECUNIA
Type: UNKNOWN
34199

Source: SECUNIA
Type: UNKNOWN
35065

Source: DEBIAN
Type: DSA-1726
python-crypto -- buffer overflow

Source: CCN
Type: Dwayne C. Litzenberger Web site
PyCrypto - The Python Cryptography Toolkit

Source: CCN
Type: GLSA-200903-11
PyCrypto: Execution of arbitrary code

Source: GENTOO
Type: UNKNOWN
GLSA-200903-11

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2009:049

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2009:050

Source: MLIST
Type: UNKNOWN
[oss-security] 20090207 CVE Request: pycrypto

Source: MLIST
Type: UNKNOWN
[oss-security] 20090212 Re: CVE Request: pycrypto

Source: CCN
Type: OSVDB ID: 51958
PyCrypto ARC2 Module ARC2 Key Length Handling Overflow

Source: BID
Type: Exploit
33674

Source: CCN
Type: BID-33674
PyCrypto ARC2 Module Buffer Overflow Vulnerability

Source: CCN
Type: USN-729-1
Python Crypto vulnerability

Source: XF
Type: UNKNOWN
pycrypto-arc2module-bo(48617)

Source: XF
Type: UNKNOWN
pycrypto-arc2module-bo(48617)

Source: SUSE
Type: SUSE-SR:2009:010
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:pycrypto:arc2:2.0.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:pycrypto:arc2:2.0.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:6.06::lts:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0::x86-64:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:7.10:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:26170
    P
    Security update for postgresql12 (Important)
    2021-11-22
    oval:org.opensuse.security:def:26106
    P
    Security update for libmspack (Moderate)
    2021-08-17
    oval:org.opensuse.security:def:20090544
    V
    CVE-2009-0544
    2021-08-15
    oval:org.opensuse.security:def:26095
    P
    Security update for glibc (Moderate)
    2021-07-27
    oval:org.opensuse.security:def:26094
    P
    Security update for curl (Moderate)
    2021-07-23
    oval:org.opensuse.security:def:36545
    P
    python-crypto-2.0.1-28.20.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26724
    P
    kdebase3-runtime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26870
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26436
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26773
    P
    libxcrypt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27508
    P
    libxslt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26520
    P
    PolicyKit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26812
    P
    python-sssd-config on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26298
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27543
    P
    python-crypto on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26671
    P
    apache2-mod_php53 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26826
    P
    syslog-ng on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26379
    P
    Security update for irssi (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:13833
    P
    USN-729-1 -- python-crypto vulnerability
    2014-06-30
    oval:org.mitre.oval:def:7473
    P
    DSA-1726 python-crypto -- buffer overflow
    2014-06-23
    oval:org.mitre.oval:def:13732
    P
    DSA-1726-1 python-crypto -- buffer overflow
    2014-06-23
    oval:org.debian:def:1726
    V
    buffer overflow
    2009-02-25
    BACK
    pycrypto arc2 2.0.1
    pycrypto arc2 2.0.1
    gentoo linux *
    canonical ubuntu 6.06
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux 2008.0
    canonical ubuntu 7.10
    mandrakesoft mandrake linux 2008.0
    mandrakesoft mandrake linux 2008.1 x86_64
    mandrakesoft mandrake linux 2008.1
    canonical ubuntu 8.04
    mandriva linux 2009.0
    mandriva linux 2009.0 -
    debian debian linux 5.0