cbcvebase.
CVE-2012-2417
published 2012-06-17

CVE-2012-2417: PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.37%
82.1th percentile
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

Affected

15 ranges
VendorProductVersion rangeFixed in
dlitzpycrypto<= 2.5
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto
dlitzpycrypto>= 0 < 2.62.6
dlitzpycrypto>= 0 < 9f912f13df99ad3421eff360d6a62d7dbec755c29f912f13df99ad3421eff360d6a62d7dbec755c2

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.