—
PYSEC-2012-16
Quick fix
PYSEC-2012-16 — pycrypto: upgrade to the fixed version with the command below.
pip install --upgrade 'pycrypto>=9f912f13df99ad3421eff360d6a62d7dbec755c2'Details
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/pycrypto
Introduced in:
0Fixed in: 9f912f13df99ad3421eff360d6a62d7dbec755c2Fix
pip install --upgrade 'pycrypto>=9f912f13df99ad3421eff360d6a62d7dbec755c2'References
- https://github.com/Legrandin/pycrypto/commit/9f912f13df99ad3421eff360d6a62d7dbec755c2[FIX]
- https://bugs.launchpad.net/pycrypto/+bug/985164[WEB]
- http://www.openwall.com/lists/oss-security/2012/05/25/1[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081789.html[WEB]
- https://github.com/dlitz/pycrypto/blob/373ea760f21701b162e8c4912a66928ee30d401a/ChangeLog[WEB]
- http://secunia.com/advisories/49263[ADVISORY]
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081759.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081713.html[WEB]
- http://www.osvdb.org/82279[WEB]
- http://www.securityfocus.com/bid/53687[WEB]
- https://hermes.opensuse.org/messages/15083589[WEB]
- http://www.debian.org/security/2012/dsa-2502[ADVISORY]
- http://www.mandriva.com/security/advisories?name=MDVSA-2012:117[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75871[WEB]
- https://github.com/advisories/GHSA-v367-p58w-98h5[ADVISORY]