Back

HIGH

python-crypto: Weak ElGamal key parameters in PublicKey/ElGamal.py allow attackers to obtain sensitive information by reading ciphertext

Published Feb 3, 2018

Description

lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.

Affected products

Remediation

Red Hat statement

Starting in Red Hat Enterprise Linux (RHEL) 8 the python-crypto is not delivered anymore, therefore RHEL 8 is not affected by this vulnerability.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 3, 2018
Updated Aug 5, 2024
Reserved Feb 2, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 3, 2018
GHSA-6528-WVF6-F6QG