CVE-2021-40529
published 2021-09-06CVE-2021-40529: The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.53%
72.2th percentile
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| botan_project | botan | <= 2.18.1 | — |
| botan_project | botan | >= 0 < 2.18.1+dfsg-3 | 2.18.1+dfsg-3 |
| botan_project | botan | >= 0 < 2.18.1+dfsg-3 | 2.18.1+dfsg-3 |
| debian | botan | < botan 2.18.1+dfsg-3 (bookworm) | botan 2.18.1+dfsg-3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mozilla | thunderbird | < 91.12.0 | 91.12.0 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-40529: botan - The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and o...
vendor_debian·2021·CVSS 5.9
CVE-2021-40529 [MEDIUM] CVE-2021-40529: botan - The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and o...
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
Scope: local
bookworm: resolved (fixed in 2.18.1+dfsg-3)
bullseye: open
trixie: resolved (fixed in 2.18.1+dfsg-3)
GHSA
GHSA-f9qg-252f-g8cg: The ElGamal implementation in Botan through 2
ghsa_unreviewed·2022-05-24
CVE-2021-40529 [MEDIUM] CWE-327 GHSA-f9qg-252f-g8cg: The ElGamal implementation in Botan through 2
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
OSV
CVE-2021-40529: The ElGamal implementation in Botan through 2
osv·2021-09-06·CVSS 5.9
CVE-2021-40529 [MEDIUM] CVE-2021-40529: The ElGamal implementation in Botan through 2
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://eprint.iacr.org/2021/923https://github.com/randombit/botan/pull/2790https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/72NB4OLD3VHJC3YF3PEP2HKF6BYURPAO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UPHGYWNJQKWLTUWBNSFB4F66MQDIL3IB/https://security.gentoo.org/glsa/202208-14https://eprint.iacr.org/2021/923https://github.com/randombit/botan/pull/2790https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/72NB4OLD3VHJC3YF3PEP2HKF6BYURPAO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UPHGYWNJQKWLTUWBNSFB4F66MQDIL3IB/https://security.gentoo.org/glsa/202208-14
2021-09-06
Published