PatchSiren cyber security CVE debrief
CVE-2013-7459 Fedoraproject CVE debrief
CVE-2013-7459 is a critical memory-corruption flaw in the Python Cryptography Toolkit (pycrypto). NVD describes it as a heap-based buffer overflow in ALGnew in block_templace.c that can be triggered with a crafted IV parameter to cryptmsg.py, and the stated impact is remote code execution. The issue was publicly discussed before the CVE record was published, and the available references point to a patch and downstream package advisories.
- Vendor
- Fedoraproject
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-15
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-15
- Advisory updated
- 2026-05-13
Who should care
Security teams, Linux/package maintainers, and developers operating applications that depend on pycrypto—especially deployments that still include pycrypto 2.6.1 or earlier, or Fedora 24/25 packages referenced in the NVD record.
Technical summary
NVD maps this issue to CWE-119 and rates it CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vulnerable code path is identified as ALGnew in block_templace.c within pycrypto, where malformed input can overflow a heap buffer. The record lists affected pycrypto versions through 2.6.1, and also marks Fedora 24 and Fedora 25 as vulnerable in the supplied CPE criteria.
Defensive priority
Urgent. Treat as a high-priority remediation item wherever pycrypto is present, because the published impact is unauthenticated network-reachable RCE with full confidentiality, integrity, and availability impact.
Recommended defensive actions
- Inventory systems and applications that bundle or import pycrypto, and flag any installation at version 2.6.1 or earlier.
- Apply the vendor or downstream patched package referenced in the corpus, or replace pycrypto with a maintained alternative if the library is no longer supported in your stack.
- Prioritize remediation on Fedora 24/25 systems referenced by the NVD CPE criteria, using the relevant package advisory channels in the source corpus.
- Review any service or utility that accepts untrusted IV or ciphertext-related inputs and confirm it is no longer using the affected code path.
- After patching, verify remediation through dependency and package inventory scans so the vulnerable library is no longer present in production images or hosts.
Evidence notes
Supported by the NVD record and linked references in the corpus: the NVD entry states a heap-based buffer overflow in ALGnew in block_templace.c and assigns CVSS 3.0 9.8 with CWE-119; the affected CPEs include dlitz:pycrypto through 2.6.1 plus Fedora 24 and 25. Public discussion is referenced via the oss-security mailing list, and remediation evidence is provided by the pycrypto patch commit and issue tracker entry. The corpus also includes downstream advisories from Red Hat and Gentoo.
Sources and references
Verified primary and authoritative sources
-
CVE-2013-7459 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2013-7459
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2013-7459 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2013-7459
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/dlitz/pycrypto/commit/8dbe0dc3eea5c689d4f76b37b93fe216cf1f00d4
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/dlitz/pycrypto/issues/176
[email protected] - Patch, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C6BWNADPLKDBBQBUT3P75W7HAJCE7M3B/
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJ37R2YLX56YZABFNAOWV4VTHTGYREAE/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.