QID 981278
QID 981278: Python (pip) Security Update for pycrypto (GHSA-6528-wvf6-f6qg)
lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6528-wvf6-f6qg for updates pertaining to this vulnerability.
Vendor References
- GHSA-6528-wvf6-f6qg -
github.com/advisories/GHSA-6528-wvf6-f6qg
CVEs related to QID 981278
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6528-wvf6-f6qg | pycrypto |
|