CVE-2012-2417
published 2012-06-17CVE-2012-2417: PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.37%
82.1th percentile
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlitz | pycrypto | <= 2.5 | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | — | — |
| dlitz | pycrypto | >= 0 < 2.6 | 2.6 |
| dlitz | pycrypto | >= 0 < 9f912f13df99ad3421eff360d6a62d7dbec755c2 | 9f912f13df99ad3421eff360d6a62d7dbec755c2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
PyCrypto makes Use of Insufficiently Random Values
ghsa·2022-05-17
CVE-2012-2417 [MEDIUM] PyCrypto makes Use of Insufficiently Random Values
PyCrypto makes Use of Insufficiently Random Values
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
OSV
PyCrypto makes Use of Insufficiently Random Values
osv·2022-05-17
CVE-2012-2417 [MEDIUM] PyCrypto makes Use of Insufficiently Random Values
PyCrypto makes Use of Insufficiently Random Values
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
OSV
CVE-2012-2417: PyCrypto before 2
osv·2012-06-17
CVE-2012-2417 CVE-2012-2417: PyCrypto before 2
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
Ubuntu
PyCrypto vulnerability
vendor_ubuntu·2012-06-28
CVE-2012-2417 PyCrypto vulnerability
Title: PyCrypto vulnerability
Summary: PyCrypto improperly created ElGamal encryption keys.
It was discovered that PyCrypto produced inappropriate prime numbers when
generating ElGamal keys. An attacker could use this flaw to facilitate
brute-forcing of ElGamal encryption keys.
Instructions: In general, a standard system update will make all the necessary changes.
If PyCrypto was used to generate ElGamal keys, we recommend they be
regenerated.
Red Hat
python-crypto: Insecure ElGamal key generation
vendor_redhat·2012-04-18·CVSS 4.3
CVE-2012-2417 [MEDIUM] python-crypto: Insecure ElGamal key generation
python-crypto: Insecure ElGamal key generation
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
Package: python-crypto (Red Hat Enterprise Linux 6) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2662 Certificate System: multiple XSS flaws
bugzilla·2012-05-30·CVSS 4.3
CVE-2012-2662 [MEDIUM] CVE-2012-2662 Certificate System: multiple XSS flaws
CVE-2012-2662 Certificate System: multiple XSS flaws
Multiple cross-site scripting issues were discovered in the Red Hat Certificate System's / Dogtag Certificate System's Agent and End Entity pages. An attacker could use these flaw to perform a cross-site scripting (XSS) attack against victims viewing Certificate System's web interface.
The issue was originally reported via bug #814478.
Following fixes were applied to address these issues:
https://fedorahosted.org/pki/changeset/2411
https://fedorahosted.org/pki/changeset/2414
https://fedorahosted.org/pki/changeset/2417
https://fedorahosted.org/pki/changeset/2426
Discussion:
This issue has been addressed in following products:
Red Hat Certificate System 8
Via RHSA-2012:1103 https://rhn.redhat.com/errata/RHSA-2012-1103.html
---
***
Bugzilla
CVE-2012-2417 python-crypto: Insecure ElGamal key generation [fedora-all]
bugzilla·2012-05-25·CVSS 4.3
CVE-2012-2417 [MEDIUM] CVE-2012-2417 python-crypto: Insecure ElGamal key generation [fedora-all]
CVE-2012-2417 python-crypto: Insecure ElGamal key generation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&b
Bugzilla
CVE-2012-2417 python-crypto: Insecure ElGamal key generation [epel-5]
bugzilla·2012-05-25·CVSS 4.3
CVE-2012-2417 [MEDIUM] CVE-2012-2417 python-crypto: Insecure ElGamal key generation [epel-5]
CVE-2012-2417 python-crypto: Insecure ElGamal key generation [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=
Bugzilla
CVE-2012-2417 python-crypto: Insecure ElGamal key generation
bugzilla·2012-05-25·CVSS 4.3
CVE-2012-2417 [MEDIUM] CVE-2012-2417 python-crypto: Insecure ElGamal key generation
CVE-2012-2417 python-crypto: Insecure ElGamal key generation
A security flaw was found in the implementation of ElGamal algorithm of python-crypto, a cryptography library for Python language, in the way how random number 'g' was generated (from the OSS post [1]):
In the ElGamal schemes (for both encryption and signatures), g is
supposed to be the generator of the entire Z^*_p group. However, in
PyCrypto 2.5 and earlier, g is more simply the generator of a random
sub-group of Z^*_p.
The result is that the signature space (when the key is used for
signing) or the public key space (when the key is used for encryption)
may be greatly reduced from its expected size of log(p) bits, possibly
down to 1 bit (the worst case if the order of g is 2).
While it has not been confirmed, it has also be
http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081713.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/081759.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/081789.htmlhttp://secunia.com/advisories/49263http://www.debian.org/security/2012/dsa-2502http://www.mandriva.com/security/advisories?name=MDVSA-2012:117http://www.openwall.com/lists/oss-security/2012/05/25/1http://www.osvdb.org/82279http://www.securityfocus.com/bid/53687https://bugs.launchpad.net/pycrypto/+bug/985164https://exchange.xforce.ibmcloud.com/vulnerabilities/75871https://github.com/Legrandin/pycrypto/commit/9f912f13df99ad3421eff360d6a62d7dbec755c2https://github.com/dlitz/pycrypto/blob/373ea760f21701b162e8c4912a66928ee30d401a/ChangeLoghttps://hermes.opensuse.org/messages/15083589http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081713.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/081759.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/081789.htmlhttp://secunia.com/advisories/49263http://www.debian.org/security/2012/dsa-2502http://www.mandriva.com/security/advisories?name=MDVSA-2012:117http://www.openwall.com/lists/oss-security/2012/05/25/1http://www.osvdb.org/82279http://www.securityfocus.com/bid/53687https://bugs.launchpad.net/pycrypto/+bug/985164https://exchange.xforce.ibmcloud.com/vulnerabilities/75871https://github.com/Legrandin/pycrypto/commit/9f912f13df99ad3421eff360d6a62d7dbec755c2https://github.com/dlitz/pycrypto/blob/373ea760f21701b162e8c4912a66928ee30d401a/ChangeLoghttps://hermes.opensuse.org/messages/15083589
2012-06-17
Published