PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py-crypto. | Aug 30, 2017 | Jun 16, 2012 |
| Freebsd | — | Upgrade py-pycrypto | Dec 10, 2025 | Jun 24, 2012 |
| Gentoo Linux | — | Upgrade dev-python/pycrypto. | Oct 30, 2017 | Jun 16, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 18, 2012 |
| Suse | — | Upgrade python-cryptoUpgrade python-pycryptoUpgrade python2-pycryptoUpgrade python3-pycrypto | Apr 26, 2018 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python-crypto | Nov 8, 2024 | Jun 17, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub