PyCryptodome integer overflow vulnerability
High severity
GitHub Reviewed
Published
Aug 27, 2018
to the GitHub Advisory Database
•
Updated Oct 21, 2024
Description
Published by the National Vulnerability Database
Aug 20, 2018
Published to the GitHub Advisory Database
Aug 27, 2018
Reviewed
Jun 16, 2020
Last updated
Oct 21, 2024
PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes.
References