Ubuntu Security Notice USN-729-1 – Mike Wiacek discovered that the ARC2 implementation in Python Crypto did not correctly check the key length. If a user or automated system were tricked into processing a malicious ARC2 stream, a remote attacker could execute arbitrary code or crash the application using Python Crypto, leading to a denial of service.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75463/USN-729-1.txt
Source: https://packetstormsecurity.com/files/75463/Ubuntu-Security-Notice-729-1.html

