Cryptographic issues in PyCrypto - CVE-2012-2417
Published: June 17, 2012 / Updated: August 11, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
Affected software
Amazon Linux AMI
Gentoo Linux
Fedora
py-crypto (Alpine package)
python-crypto
IBM Cloud Pak System
IBM Watson Machine Learning Accelerator
How to mitigate CVE-2012-2417
IBM Cloud Pak System - update to 2.3.3.6
python-crypto - update to 2.0.1-5.el5
IBM Watson Machine Learning Accelerator - update to 4.0
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081713.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081759.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081789.html
- http://secunia.com/advisories/49263
- http://www.debian.org/security/2012/dsa-2502
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:117
- http://www.openwall.com/lists/oss-security/2012/05/25/1
- http://www.osvdb.org/82279
- http://www.securityfocus.com/bid/53687
- https://bugs.launchpad.net/pycrypto/+bug/985164
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75871
- https://github.com/dlitz/pycrypto/blob/373ea760f21701b162e8c4912a66928ee30d401a/ChangeLog
- https://github.com/Legrandin/pycrypto/commit/9f912f13df99ad3421eff360d6a62d7dbec755c2
- https://hermes.opensuse.org/messages/15083589
Related Security Bulletins
- Cryptographic issues in GNU PyCrypto
- Cryptographic issues in py-crypto (Alpine package)
- Amazon Linux AMI update for python-crypto
- Gentoo update for PyCrypto
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Fedora EPEL 5 update for python-crypto