PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2502-1 python-crypto security update
EUVD EUVD EUVD-2012-0026 PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
Github GHSA Github GHSA GHSA-v367-p58w-98h5 PyCrypto makes Use of Insufficiently Random Values
Ubuntu USN Ubuntu USN USN-1484-1 PyCrypto vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T19:34:25.430Z

Reserved: 2012-04-24T00:00:00

Link: CVE-2012-2417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-06-17T03:41:40.763

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-2417

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-04-18T00:00:00Z

Links: CVE-2012-2417 - Bugzilla

cve-icon OpenCVE Enrichment

No data.