← Back

CVE-2012-2417

nvd nist
Published: Jun 17, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

Affected (21)

Products: Dlitz: Pycrypto
1 product
Pycrypto
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Dlitz
Up to 2.5
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.1 alpha2
Version 1.9 alpha1
Version 1.9 alpha2
Version 1.9 alpha3
Version 1.9 alpha4
Version 1.9 alpha5
Version 1.9 alpha6
Version 2.0.1
Version 2.0
Version 2.1.0
Version 2.1.0 alpha1
Version 2.1.0 alpha2
Version 2.1.0 beta1
Version 2.2
Version 2.3
Version 2.4.1
Version 2.4

Related CWEs

References (28)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.