Vulnerability Name:

CVE-2013-1445 (CCN-88132)

Assigned:2013-10-17
Published:2013-10-17
Updated:2013-10-28
Summary:The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is created and accesses the PRNG within the same rate-limit period as another process.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-310
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2013-1445

Source: CCN
Type: oss-sec Mailing List, Thu, 17 Oct 2013 09:28:41 -0700
CVE-2013-1445 python-crypto: PRNG not correctly reseeded in some situations

Source: DEBIAN
Type: UNKNOWN
DSA-2781

Source: DEBIAN
Type: DSA-2781
python-crypto -- PRNG not correctly reseeded in some situations

Source: MLIST
Type: Exploit, Patch
[oss-security] 20131017 CVE-2013-1445 python-crypto:PRNG not correctly reseeded in some situations

Source: CCN
Type: BID-63201
PyCrypto 'Crypto.Random' Race Condition Information Disclosure Weakness

Source: XF
Type: UNKNOWN
pycrypto-cve20131445-info-disc(88132)

Source: CCN
Type: PyCrypto GIT Repository
PyCrypto

Source: CONFIRM
Type: Exploit
https://github.com/dlitz/pycrypto/commit/19dcf7b15d61b7dc1a125a367151de40df6ef175

Vulnerable Configuration:Configuration 1:
  • cpe:/a:dlitz:pycrypto:1.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:1.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:2.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:2.2:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:2.3:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:2.4:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:2.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:2.5:*:*:*:*:*:*:*
  • OR cpe:/a:dlitz:pycrypto:*:*:*:*:*:*:*:* (Version <= 2.6)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:551
    P
    Security update for python-Twisted (Important)
    2022-07-06
    oval:org.opensuse.security:def:20131445
    V
    CVE-2013-1445
    2022-06-30
    oval:org.opensuse.security:def:256
    P
    pam_krb5-2.4.13-1.36 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:964
    P
    Security update for the Linux Kernel (Important)
    2022-03-08
    oval:org.opensuse.security:def:113217
    P
    python-pycrypto-2.6.1-4.8 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:7008
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 15 SP1) (Important)
    2021-12-14
    oval:org.opensuse.security:def:6983
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) (Important)
    2021-11-17
    oval:org.opensuse.security:def:67798
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 15) (Important)
    2021-10-12
    oval:org.opensuse.security:def:7710
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:1485
    P
    Security update for ffmpeg (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:106635
    P
    python-pycrypto-2.6.1-4.8 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:55250
    P
    Security update for sqlite3 (Important)
    2021-09-23
    oval:org.opensuse.security:def:96760
    P
    python3-pycrypto-2.6.1-1.28 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71280
    P
    libmpfr6-4.0.1-1.46 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61640
    P
    python3-pycrypto-2.6.1-1.28 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103450
    P
    python3-pycrypto-2.6.1-1.28 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71151
    P
    btrfsmaintenance-0.4.2-1.11 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71381
    P
    python3-pycrypto-2.6.1-1.28 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89795
    P
    python3-pycrypto-2.6.1-1.28 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71393
    P
    shadow-4.6-1.31 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:68040
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP1) (Important)
    2021-08-17
    oval:org.opensuse.security:def:47838
    P
    ovmf-2017+git1510945757.b2662641d5-2.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47776
    P
    libquicktime0-1.2.4-14.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47692
    P
    libapr1-1.5.1-4.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47478
    P
    python-PyYAML-3.12-25.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47330
    P
    libapr1-1.5.1-2.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47072
    P
    libruby2_1-2_1-2.1.2-12.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47238
    P
    dbus-1-1.8.22-28.19 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47106
    P
    mozilla-nspr-32bit-4.12-15.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48300
    P
    ruby-2.1-1.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46913
    P
    cron-4.2-58.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48229
    P
    libxslt-tools-1.1.28-17.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48198
    P
    libsqlite3-0-3.8.10.2-9.12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48133
    P
    libjbig2-2.0-12.13 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48071
    P
    libX11-6-1.6.2-12.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47987
    P
    cyrus-sasl-2.1.26-8.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47773
    P
    libpython3_4m1_0-3.4.6-25.16.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47625
    P
    gnome-shell-3.20.4-77.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47485
    P
    python-requests-2.8.1-6.16.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47533
    P
    xinetd-2.3.15-7.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47401
    P
    libpython3_4m1_0-3.4.6-24.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47208
    P
    at-3.1.14-7.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47087
    P
    libtiff5-32bit-4.0.6-26.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47073
    P
    libsmi-0.4.8-18.55 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48186
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48038
    P
    gv-3.7.4-1.36 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47946
    P
    apache-commons-beanutils-1.9.2-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47814
    P
    libxml2-2-2.9.4-46.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47621
    P
    glib2-lang-2.48.2-10.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47500
    P
    shim-0.9-23.14 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47486
    P
    python3-3.4.6-24.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48005
    P
    fetchmail-6.3.26-12.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47934
    P
    zoo-2.10-1020.56 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47903
    P
    tcpdump-4.9.2-14.5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:55933
    P
    Security update for cpio (Important)
    2021-08-14
    oval:org.opensuse.security:def:6908
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 15 SP1) (Important)
    2021-06-18
    oval:org.opensuse.security:def:48938
    P
    libpcrecpp0-32bit-8.39-8.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71038
    P
    libunwind-1.2.1-2.13 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48697
    P
    libuuid-devel-2.25-6.69 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46792
    P
    mailman-2.1.17-1.18 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46778
    P
    libtiff5-32bit-4.0.4-12.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61345
    P
    python2-pycrypto-2.6.1-1.28 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36498
    P
    libupsclient1-2.6.2-0.2.4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48713
    P
    colord-1.1.7-5.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71086
    P
    python2-pycrypto-2.6.1-1.28 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48642
    P
    vorbis-tools-1.4.0-26.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48611
    P
    qemu-2.6.1-27.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48546
    P
    libruby2_1-2_1-2.1.2-12.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48484
    P
    libblkid1-2.28-40.28 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:5726
    P
    Security update for the Linux Kernel (Important)
    2021-06-08
    oval:org.opensuse.security:def:48400
    P
    dbus-1-1.8.16-19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48643
    P
    vsftpd-3.0.2-31.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36540
    P
    postgresql-devel-8.3.23-0.4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46777
    P
    libtasn1-3.7-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64693
    P
    Security update for hivex (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:7072
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP2) (Important)
    2021-04-28
    oval:org.opensuse.security:def:6889
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-04-28
    oval:org.opensuse.security:def:7059
    P
    Security update for the Linux Kernel (Live Patch 7 for SLE 15 SP2) (Important)
    2021-04-07
    oval:org.opensuse.security:def:6874
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP1) (Important)
    2021-04-07
    oval:org.opensuse.security:def:64606
    P
    Security update for python (Important)
    2021-02-09
    oval:org.opensuse.security:def:5748
    P
    Security update for clamav-database (Important)
    2021-01-25
    oval:org.opensuse.security:def:64451
    P
    Security update for ceph (Important)
    2020-12-21
    oval:org.opensuse.security:def:35233
    P
    Security update for python (Important)
    2020-12-11
    oval:org.opensuse.security:def:7050
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:67940
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) (Important)
    2020-12-07
    oval:org.opensuse.security:def:46361
    P
    python-pycrypto-2.6.1-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13241
    P
    python-pycrypto-2.6.1-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48992
    P
    gstreamer-0_10-plugins-bad-0.10.23-25.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35860
    P
    acpid-1.0.6-91.25.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35816
    P
    quagga-0.99.15-0.6.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35788
    P
    nagios-3.0.6-1.25.24.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35749
    P
    libgtop-2.28.0-1.2.20 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35700
    P
    freetype2-2.3.7-25.28.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35641
    P
    syslog-ng-2.0.9-27.27.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:11256
    P
    python-pycrypto-2.6.1-1.18 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:5088
    P
    Security update for the Linux Kernel (Important)
    2020-12-02
    oval:org.opensuse.security:def:5075
    P
    Security update for rubygem-activesupport-5_1 (Critical)
    2020-12-02
    oval:org.opensuse.security:def:5066
    P
    Security update for the Linux Kernel (Important)
    2020-12-02
    oval:org.opensuse.security:def:5057
    P
    Security update for haproxy (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4767
    P
    Security update for freeradius-server (Important)
    2020-12-02
    oval:org.opensuse.security:def:5024
    P
    Security update for nodejs10 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4999
    P
    Security update for php7 (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4924
    P
    Security update for freetds (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4905
    P
    Security update for rmt-server (Important)
    2020-12-02
    oval:org.opensuse.security:def:4890
    P
    Security update for postgresql12 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4843
    P
    Security update for apache2 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4797
    P
    Security update for sysstat (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4775
    P
    Security update for libvirt (Important)
    2020-12-02
    oval:org.opensuse.security:def:35002
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:55661
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:55488
    P
    Security update for libarchive (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55110
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55088
    P
    cyrus-sasl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67698
    P
    libmspack-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49872
    P
    python2-numpy-gnu-hpc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7041
    P
    libgif6-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6751
    P
    libraw9 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7732
    P
    python-pycrypto on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64364
    P
    libpango-1_0-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35001
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6827
    P
    python-requests on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6781
    P
    libxcb-dri2-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49926
    P
    python2-pycrypto on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6759
    P
    libspice-client-glib-2_0-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55087
    P
    cvs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56611
    P
    Security update for texlive (Important)
    2020-12-01
    oval:org.opensuse.security:def:56530
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35481
    P
    Recommended update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56492
    P
    Security update for kernel-firmware (Important)
    2020-12-01
    oval:org.opensuse.security:def:35391
    P
    Security update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56418
    P
    Security update for perl-XML-LibXML (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35334
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:56326
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56218
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35097
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:35013
    P
    Security update for gpg2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:55767
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.mitre.oval:def:19624
    P
    DSA-2781-1 python-crypto - PRNG not correctly reseeded in some situations
    2014-06-23
    oval:com.ubuntu.artful:def:20131445000
    V
    CVE-2013-1445 on Ubuntu 17.10 (artful) - low.
    2013-10-26
    oval:com.ubuntu.trusty:def:20131445000
    V
    CVE-2013-1445 on Ubuntu 14.04 LTS (trusty) - low.
    2013-10-26
    oval:com.ubuntu.cosmic:def:201314450000000
    V
    CVE-2013-1445 on Ubuntu 18.10 (cosmic) - low.
    2013-10-26
    oval:com.ubuntu.bionic:def:20131445000
    V
    CVE-2013-1445 on Ubuntu 18.04 LTS (bionic) - low.
    2013-10-26
    oval:com.ubuntu.xenial:def:20131445000
    V
    CVE-2013-1445 on Ubuntu 16.04 LTS (xenial) - low.
    2013-10-26
    oval:com.ubuntu.bionic:def:201314450000000
    V
    CVE-2013-1445 on Ubuntu 18.04 LTS (bionic) - low.
    2013-10-26
    oval:com.ubuntu.cosmic:def:20131445000
    V
    CVE-2013-1445 on Ubuntu 18.10 (cosmic) - low.
    2013-10-26
    oval:com.ubuntu.xenial:def:201314450000000
    V
    CVE-2013-1445 on Ubuntu 16.04 LTS (xenial) - low.
    2013-10-26
    oval:com.ubuntu.precise:def:20131445000
    V
    CVE-2013-1445 on Ubuntu 12.04 LTS (precise) - low.
    2013-10-26
    BACK
    dlitz pycrypto 1.0.0
    dlitz pycrypto 1.0.1
    dlitz pycrypto 1.0.2
    dlitz pycrypto 2.0
    dlitz pycrypto 2.0.1
    dlitz pycrypto 2.1.0
    dlitz pycrypto 2.2
    dlitz pycrypto 2.3
    dlitz pycrypto 2.4
    dlitz pycrypto 2.4.1
    dlitz pycrypto 2.5
    dlitz pycrypto *