Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6594

Опубликовано: 03 фев. 2018
Источник: debian

Описание

lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pycryptodomefixed3.4.11-1package
python-cryptofixed2.6.1-9package
python-cryptono-dsastretchpackage
python-cryptono-dsajessiepackage
python-cryptono-dsawheezypackage

Примечания

  • PyCrypto: https://github.com/dlitz/pycrypto/issues/253

  • The issue is found as well in pycryptodome (fork from python-crypto)

  • PyCryptodome: https://github.com/Legrandin/pycryptodome/issues/90

  • PyCrytpodome: https://github.com/Legrandin/pycryptodome/commit/99c27a3b9e8a884bbde0e88c63234b669d4398d8 (3.4.10)

  • See further discussion as per https://github.com/Legrandin/pycryptodome/issues/90#issuecomment-362783537

  • Upstream feels that this is not a vulnerability in pycryptodome/python-crypto,

  • but in an application using it in an insecure manner.

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.

CVSS3: 5.3
redhat
около 8 лет назад

lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.

CVSS3: 7.5
nvd
около 8 лет назад

lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.

CVSS3: 7.5
github
больше 7 лет назад

Pycrypto generates weak key parameters

CVSS3: 7.5
fstec
около 8 лет назад

Уязвимость пакета, содержащего криптографические алгоритмы и протоколы для Python, Python-crypto, связанная с генерацией слабых ключевых параметров, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным