CVE-2018-10903
published 2018-07-30CVE-2018-10903: A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
3.20%
86.7th percentile
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| cryptography.io | cryptography | >= 1.9.0 < 2.3 | 2.3 |
| cryptography | python-cryptography | >= 0 < 2.3-1 | 2.3-1 |
| cryptography | python-cryptography | >= 0 < 2.3-1 | 2.3-1 |
| cryptography | python-cryptography | >= 0 < 2.3-1 | 2.3-1 |
| cryptography | python-cryptography | >= 0 < 2.3-1 | 2.3-1 |
| cryptography | python-cryptography | >= 1.9.0 < 2.3 | 2.3 |
| debian | python-cryptography | < python-cryptography 2.3-1 (bookworm) | python-cryptography 2.3-1 (bookworm) |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
python-cryptography vulnerability
vendor_ubuntu·2018-07-23
CVE-2018-10903 python-cryptography vulnerability
Title: python-cryptography vulnerability
Summary: python-cryptography could be made to expose sensitive information
if it received a specially crafted input.
It was discovered that python-cryptography incorrectly handled certain inputs.
An attacker could possibly use this to get access to sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API
vendor_redhat·2018-07-18·CVSS 7.5
CVE-2018-10903 [HIGH] CWE-20 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API
python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API
A flaw was found in python-cryptography versions between >=1.9.0 and =1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
Package: python-cryptography (Red Hat Enterprise Linux 7) - Not affected
Package: python-cryptography (Red Hat Enterprise Linux 8) - Not affected
Package: python-cryptography (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Not affected
Package: python-cryptography (Red Hat OpenStac
Debian
CVE-2018-10903: python-cryptography - A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The f...
vendor_debian·2018·CVSS 7.5
CVE-2018-10903 [HIGH] CVE-2018-10903: python-cryptography - A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The f...
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
Scope: local
bookworm: resolved (fixed in 2.3-1)
bullseye: resolved (fixed in 2.3-1)
forky: resolved (fixed in 2.3-1)
sid: resolved (fixed in 2.3-1)
trixie: resolved (fixed in 2.3-1)
OSV
PyCA Cryptography vulnerable to GCM tag forgery
osv·2018-07-31
CVE-2018-10903 [HIGH] PyCA Cryptography vulnerable to GCM tag forgery
PyCA Cryptography vulnerable to GCM tag forgery
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
GHSA
PyCA Cryptography vulnerable to GCM tag forgery
ghsa·2018-07-31
CVE-2018-10903 [HIGH] CWE-20 PyCA Cryptography vulnerable to GCM tag forgery
PyCA Cryptography vulnerable to GCM tag forgery
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
OSV
CVE-2018-10903: A flaw was found in python-cryptography versions between >=1
osv·2018-07-30·CVSS 7.5
CVE-2018-10903 [HIGH] CVE-2018-10903: A flaw was found in python-cryptography versions between >=1
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-10903 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API [openstack-rdo]
bugzilla·2018-07-20·CVSS 7.5
CVE-2018-10903 [HIGH] CVE-2018-10903 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API [openstack-rdo]
CVE-2018-10903 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
htt
Bugzilla
CVE-2018-10903 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API
bugzilla·2018-07-18·CVSS 7.5
CVE-2018-10903 [HIGH] CVE-2018-10903 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API
CVE-2018-10903 python-cryptography: GCM tag forgery via truncated tag in finalize_with_tag API
A flaw was found in python-cryptography versions between >=1.9.0 and RHEL7.5 ships version 1.7.2-2. Thus it is affected.
How come, description says >=1.9.0 and <2.3 ?
---
Correction: RHEL7.5 ships version 1.7.2-2 and the finalize_with_tag method wasn't implemented in this version. Thus it is NOT affected. I am closing the rhel-7 tracker.
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 13.0 (Queens)
Via RHSA-2018:3600 https://access.redhat.com/errata/RHSA-2018:3600
https://access.redhat.com/errata/RHSA-2018:3600https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10903https://github.com/pyca/cryptography/pull/4342/commits/688e0f673bfbf43fa898994326c6877f00ab19efhttps://usn.ubuntu.com/3720-1/https://access.redhat.com/errata/RHSA-2018:3600https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10903https://github.com/pyca/cryptography/pull/4342/commits/688e0f673bfbf43fa898994326c6877f00ab19efhttps://usn.ubuntu.com/3720-1/
2018-07-30
Published