Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5793
HistoryFeb 06, 2018 - 12:58 a.m.

Weak ElGamal Parameters

2018-02-0600:58:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.003 Low

EPSS

Percentile

71.2%

PyCrypto uses weak ElGamal cryptography. Due to an incorrect implementation of ElGamal, the Decisional Diffie-Hellman (DDH) assumption doesn’t hold because of the way the key parameters are generated. This allows attackers who have access to the cipher-text to decrypt the messages and potentially gain access to sensitive information.