[pycrypto] Any progress with pycrypto 2.7?

Dwayne Litzenberger dlitz at dlitz.net
Thu Feb 6 09:55:24 PST 2014


On Mon, Jan 27, 2014 at 10:35:28PM +0100, Legrandin wrote:
>The current alpha1 version contains a few critical bugs which make it
>highly unsuitable for release:
>1) Hard crash on recent recent Intel CPUs (due gcc and AESNI)
>2) Potential DoS when importing an RSA key (segfault of the interpreter)
>3) Silent, incorrect HMAC construction for SHA-2
>
>Is there any chance the relevant patches are applied on the short term?
>It would be great to fix at least the version which is available from
>download from the website.

I'll see if I can find some time this weekend to take care of some of 
these issues.

-- 
Dwayne C. Litzenberger <dlitz at dlitz.net>
  OpenPGP: 19E1 1FE8 B3CF F273 ED17  4A24 928C EC13 39C2 5CF7


More information about the pycrypto mailing list