CVE-2012-2417
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
17/06/2012
Last modified:
11/04/2025
Description
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:dlitz:pycrypto:*:*:*:*:*:*:*:* | 2.5 (including) | |
cpe:2.3:a:dlitz:pycrypto:1.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.1:alpha2:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.9:alpha1:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.9:alpha2:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.9:alpha3:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.9:alpha4:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.9:alpha5:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:1.9:alpha6:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:2.1.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:dlitz:pycrypto:2.1.0:alpha1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081713.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081759.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081789.html
- http://secunia.com/advisories/49263
- http://www.debian.org/security/2012/dsa-2502
- http://www.mandriva.com/security/advisories?name=MDVSA-2012%3A117
- http://www.openwall.com/lists/oss-security/2012/05/25/1
- http://www.osvdb.org/82279
- http://www.securityfocus.com/bid/53687
- https://bugs.launchpad.net/pycrypto/+bug/985164
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75871
- https://github.com/Legrandin/pycrypto/commit/9f912f13df99ad3421eff360d6a62d7dbec755c2
- https://github.com/dlitz/pycrypto/blob/373ea760f21701b162e8c4912a66928ee30d401a/ChangeLog
- https://hermes.opensuse.org/messages/15083589
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081713.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081759.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081789.html
- http://secunia.com/advisories/49263
- http://www.debian.org/security/2012/dsa-2502
- http://www.mandriva.com/security/advisories?name=MDVSA-2012%3A117
- http://www.openwall.com/lists/oss-security/2012/05/25/1
- http://www.osvdb.org/82279
- http://www.securityfocus.com/bid/53687
- https://bugs.launchpad.net/pycrypto/+bug/985164
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75871
- https://github.com/Legrandin/pycrypto/commit/9f912f13df99ad3421eff360d6a62d7dbec755c2
- https://github.com/dlitz/pycrypto/blob/373ea760f21701b162e8c4912a66928ee30d401a/ChangeLog
- https://hermes.opensuse.org/messages/15083589