MGASA-2018-0171
Dashboard / Vulnerabilities / MGASA-2018-0171
Summary: Updated python-pycrypto packages fix security vulnerability
Details: The textbook ElGamal implementation is not secure. PyCrypto and some other implementations use the wrong algorithm, which may lead to some information disclosure simply by looking at the encrypted text. For a full description, see https://github.com/dlitz/pycrypto/issues/253 This update includes a fix for this problem backported from pycryptodome.
References: https://advisories.mageia.org/MGASA-2018-0171.html, https://bugs.mageia.org/show_bug.cgi?id=22693, https://github.com/TElgamal/attack-on-pycrypto-elgamal, https://github.com/Legrandin/pycryptodome/issues/90, https://github.com/dlitz/pycrypto/issues/253
Affected packages
Package
Name: python-pycrypto
Purl: pkg:rpm/mageia/python-pycrypto?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
