CVE-2018-10903
Summary
| CVE | CVE-2018-10903 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-30 16:29:00 UTC |
| Updated | 2021-08-04 17:14:00 UTC |
| Description | A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1602931 – (CVE-2018-10903) CVE-2018-10903 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| USN-3720-1: python-cryptography vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| disallow implicit tag truncation with finalize_with_tag by reaperhulk · Pull Request #4342 · pyca/cryptography · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 752812 SUSE Enterprise Linux Security Update for python-cryptography, python-cryptography-vectors (SUSE-SU-2022:4044-1)
- 981113 Python (pip) Security Update for cryptography (GHSA-fcf9-3qw3-gxmj)