Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v367-p58w-98h5

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

PyCrypto makes Use of Insufficiently Random Values

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

Пакеты

Наименование

PyCrypto

pip
Затронутые версииВерсия исправления

< 2.6

2.6

EPSS

Процентиль: 88%
0.04088
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
больше 13 лет назад

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

redhat
почти 14 лет назад

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

nvd
больше 13 лет назад

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

debian
больше 13 лет назад

PyCrypto before 2.6 does not produce appropriate prime numbers when us ...

EPSS

Процентиль: 88%
0.04088
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3