CVE-2018-15560

PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pycryptodome:pycryptodome:*:*:*:*:*:*:*:*

History

11 Jan 2024, 15:28

Type Values Removed Values Added
CPE cpe:2.3:a:python:pycryptodome:*:*:*:*:*:*:*:* cpe:2.3:a:pycryptodome:pycryptodome:*:*:*:*:*:*:*:*
First Time Pycryptodome
Pycryptodome pycryptodome

Information

Published : 2018-08-20 00:29

Updated : 2024-01-11 15:28


NVD link : CVE-2018-15560

Mitre link : CVE-2018-15560

CVE.ORG link : CVE-2018-15560


JSON object : View

Products Affected

pycryptodome

  • pycryptodome
CWE
CWE-190

Integer Overflow or Wraparound