VDB
Sign up
—

PYSEC-2012-16

Quick fix

PYSEC-2012-16 — pycrypto: upgrade to the fixed version with the command below.

pip install --upgrade 'pycrypto>=9f912f13df99ad3421eff360d6a62d7dbec755c2'

Details

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pycrypto
Introduced in: 0Fixed in: 9f912f13df99ad3421eff360d6a62d7dbec755c2
Fixpip install --upgrade 'pycrypto>=9f912f13df99ad3421eff360d6a62d7dbec755c2'

References