viper-framework/viper

Rats modules using outdated crypto library

Open

#710 aberto em 14 de out. de 2018

Ver no GitHub
 (2 comments) (0 reactions) (0 assignees)Python (372 forks)batch import
help wanted

Métricas do repositório

Stars
 (1.527 stars)
Métricas de merge de PR
 (Nenhuma PRs mesclada em 30d)

Description

There are several modules in the rats/ folder by @kevthehermit that are using a crypto library called pycrypto, mostly for AES and DES support. Unfortunately, this library hasn't been updated since 2014 and also has a vulnerable ElGamal implementation: https://nvd.nist.gov/vuln/detail/CVE-2018-6594

We should update these modules to make use of cryptography instead and drop pycrypto all together from our dependencies.

Guia do colaborador