Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v367-p58w-98h5

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

PyCrypto makes Use of Insufficiently Random Values

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

Пакеты

Наименование

PyCrypto

pip
Затронутые версииВерсия исправления

< 2.6

2.6

EPSS

Процентиль: 82%
0.02393
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
около 14 лет назад

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

redhat
больше 14 лет назад

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

nvd
около 14 лет назад

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

debian
около 14 лет назад

PyCrypto before 2.6 does not produce appropriate prime numbers when us ...

EPSS

Процентиль: 82%
0.02393
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3