Lucene search

K
cve[email protected]CVE-2012-2417
HistoryJun 17, 2012 - 3:41 a.m.

CVE-2012-2417

2012-06-1703:41:40
CWE-310
web.nvd.nist.gov
33
4
pycrypto
elgamal
prime numbers
key generation
signature space
public key space
brute force attack
private key

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.6%

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

Affected configurations

NVD
Node
dlitzpycryptoRange≀2.5
OR
dlitzpycryptoMatch1.0.0
OR
dlitzpycryptoMatch1.0.1
OR
dlitzpycryptoMatch1.0.2
OR
dlitzpycryptoMatch1.1alpha2
OR
dlitzpycryptoMatch1.9alpha1
OR
dlitzpycryptoMatch1.9alpha2
OR
dlitzpycryptoMatch1.9alpha3
OR
dlitzpycryptoMatch1.9alpha4
OR
dlitzpycryptoMatch1.9alpha5
OR
dlitzpycryptoMatch1.9alpha6
OR
dlitzpycryptoMatch2.0
OR
dlitzpycryptoMatch2.0.1
OR
dlitzpycryptoMatch2.1.0
OR
dlitzpycryptoMatch2.1.0alpha1
OR
dlitzpycryptoMatch2.1.0alpha2
OR
dlitzpycryptoMatch2.1.0beta1
OR
dlitzpycryptoMatch2.2
OR
dlitzpycryptoMatch2.3
OR
dlitzpycryptoMatch2.4
OR
dlitzpycryptoMatch2.4.1

Social References

More

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.6%