~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2018-6594

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2018-02-03
2
 
Candidate: CVE-2018-6594
3
 
PublicDate: 2018-02-03
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6594
6
 
 https://github.com/TElgamal/attack-on-pycrypto-elgamal
7
 
 https://usn.ubuntu.com/usn/usn-3616-1
8
 
 https://usn.ubuntu.com/usn/usn-3616-2
9
 
Description:
10
 
 lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak
11
 
 ElGamal key parameters, which allows attackers to obtain sensitive
12
 
 information by reading ciphertext data (i.e., it does not have semantic
13
 
 security in face of a ciphertext-only attack). The Decisional
14
 
 Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal
15
 
 implementation.
16
 
Ubuntu-Description:
17
 
Notes:
18
 
Bugs:
19
 
 https://github.com/dlitz/pycrypto/issues/253
20
 
 https://github.com/Legrandin/pycryptodome/issues/90
21
 
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889999 (python-crypto)
22
 
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=889998 (pycryptodome)
23
 
Priority: medium
24
 
Discovered-by:
25
 
Assigned-to: mdeslaur
26
 
 
27
 
Patches_python-crypto:
28
 
 other: https://github.com/pghmcfc/pycrypto/commit/2f6c124e127b5dd98723e7e75a9825c4ed8bd5c7
29
 
upstream_python-crypto: needs-triage
30
 
precise/esm_python-crypto: released (2.4.1-1ubuntu0.3)
31
 
trusty_python-crypto: released (2.6.1-4ubuntu0.3)
32
 
xenial_python-crypto: released (2.6.1-6ubuntu0.16.04.3)
33
 
artful_python-crypto: released (2.6.1-7ubuntu0.1)
34
 
bionic_python-crypto: released (2.6.1-8ubuntu2)
35
 
devel_python-crypto: released (2.6.1-8ubuntu2)
36
 
 
37
 
Patches_pycryptodome:
38
 
 upstream: https://github.com/Legrandin/pycryptodome/commit/99c27a3b9e8a884bbde0e88c63234b669d4398d8
39
 
upstream_pycryptodome: needs-triage
40
 
precise/esm_pycryptodome: DNE
41
 
trusty_pycryptodome: DNE
42
 
xenial_pycryptodome: DNE
43
 
artful_pycryptodome: needed
44
 
bionic_pycryptodome: released (3.4.7-1ubuntu1)
45
 
devel_pycryptodome: released (3.4.7-1ubuntu1)