viper-framework/viper

Rats modules using outdated crypto library

Open

#710 ouverte le 14 oct. 2018

Voir sur GitHub
 (2 commentaires) (0 réactions) (0 assignés)Python (372 forks)batch import
help wanted

Métriques du dépôt

Stars
 (1 527 stars)
Métriques de merge PR
 (Aucune PR mergée en 30 j)

Description

There are several modules in the rats/ folder by @kevthehermit that are using a crypto library called pycrypto, mostly for AES and DES support. Unfortunately, this library hasn't been updated since 2014 and also has a vulnerable ElGamal implementation: https://nvd.nist.gov/vuln/detail/CVE-2018-6594

We should update these modules to make use of cryptography instead and drop pycrypto all together from our dependencies.

Guide contributeur