CVE-2012-2417

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
17/06/2012
Last modified:
11/04/2025

Description

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dlitz:pycrypto:*:*:*:*:*:*:*:* 2.5 (including)
cpe:2.3:a:dlitz:pycrypto:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.1:alpha2:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.9:alpha1:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.9:alpha2:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.9:alpha3:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.9:alpha4:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.9:alpha5:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:1.9:alpha6:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:2.0:*:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:dlitz:pycrypto:2.1.0:alpha1:*:*:*:*:*:*


References to Advisories, Solutions, and Tools