viper-framework/viper

Rats modules using outdated crypto library

Open

#710 aperta il 14 ott 2018

Vedi su GitHub
 (2 commenti) (0 reazioni) (0 assegnatari)Python (372 fork)batch import
help wanted

Metriche repository

Star
 (1527 star)
Metriche merge PR
 (Nessuna PR mergiata in 30 g)

Descrizione

There are several modules in the rats/ folder by @kevthehermit that are using a crypto library called pycrypto, mostly for AES and DES support. Unfortunately, this library hasn't been updated since 2014 and also has a vulnerable ElGamal implementation: https://nvd.nist.gov/vuln/detail/CVE-2018-6594

We should update these modules to make use of cryptography instead and drop pycrypto all together from our dependencies.

Guida contributor