Vulnerability Database

296,202

Total vulnerabilities in the database

CVE-2012-2417

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

  • Published: Jun 17, 2012
  • Updated: Apr 13, 2023
  • CVE: CVE-2012-2417
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N

CWEs:

Software From Fixed in
dlitz / pycrypto 1.9-alpha5 1.9-alpha5.x
dlitz / pycrypto 1.9-alpha1 1.9-alpha1.x
dlitz / pycrypto 2.2 2.2.x
dlitz / pycrypto 1.9-alpha2 1.9-alpha2.x
dlitz / pycrypto 2.1.0-beta1 2.1.0-beta1.x
dlitz / pycrypto 1.0.1 1.0.1.x
dlitz / pycrypto 2.0.1 2.0.1.x
dlitz / pycrypto 2.0 2.0.x
dlitz / pycrypto 2.4.1 2.4.1.x
dlitz / pycrypto 1.1-alpha2 1.1-alpha2.x
dlitz / pycrypto 1.9-alpha4 1.9-alpha4.x
dlitz / pycrypto 2.1.0 2.1.0.x
dlitz / pycrypto 2.4 2.4.x
dlitz / pycrypto 2.1.0-alpha1 2.1.0-alpha1.x
dlitz / pycrypto - 2.5.x
dlitz / pycrypto 1.0.2 1.0.2.x
dlitz / pycrypto 1.9-alpha6 1.9-alpha6.x
dlitz / pycrypto 2.1.0-alpha2 2.1.0-alpha2.x
dlitz / pycrypto 1.9-alpha3 1.9-alpha3.x
dlitz / pycrypto 2.3 2.3.x
dlitz / pycrypto 1.0.0 1.0.0.x