4.3

CVE-2012-2417

Exploit

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key.

Data is provided by the National Vulnerability Database (NVD)
DlitzPycrypto Version <= 2.5
DlitzPycrypto Version1.0.0
DlitzPycrypto Version1.0.1
DlitzPycrypto Version1.0.2
DlitzPycrypto Version1.1 Updatealpha2
DlitzPycrypto Version1.9 Updatealpha1
DlitzPycrypto Version1.9 Updatealpha2
DlitzPycrypto Version1.9 Updatealpha3
DlitzPycrypto Version1.9 Updatealpha4
DlitzPycrypto Version1.9 Updatealpha5
DlitzPycrypto Version1.9 Updatealpha6
DlitzPycrypto Version2.0
DlitzPycrypto Version2.0.1
DlitzPycrypto Version2.1.0
DlitzPycrypto Version2.1.0 Updatealpha1
DlitzPycrypto Version2.1.0 Updatealpha2
DlitzPycrypto Version2.1.0 Updatebeta1
DlitzPycrypto Version2.2
DlitzPycrypto Version2.3
DlitzPycrypto Version2.4
DlitzPycrypto Version2.4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.09% 0.875
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N