UBUNTU-CVE-2018-6594
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-6594
UBUNTU-CVE-2018-6594
Summary:
Details: lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.
References: https://ubuntu.com/security/CVE-2018-6594, https://github.com/TElgamal/attack-on-pycrypto-elgamal, https://ubuntu.com/security/notices/USN-3616-1, https://ubuntu.com/security/notices/USN-3616-2, https://www.cve.org/CVERecord?id=CVE-2018-6594
Affected packages
Package
Name: python-crypto
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
