{"id":"MGASA-2018-0171","summary":"Updated python-pycrypto packages fix security vulnerability","details":"The textbook ElGamal implementation is not secure. PyCrypto and some\nother implementations use the wrong algorithm, which may lead to some\ninformation disclosure simply by looking at the encrypted text. For a\nfull description, see https://github.com/dlitz/pycrypto/issues/253\nThis update includes a fix for this problem backported from pycryptodome.\n","modified":"2026-04-16T06:24:34.142701260Z","published":"2018-03-19T12:13:14Z","upstream":["CVE-2018-6594"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0171.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=22693"},{"type":"WEB","url":"https://github.com/TElgamal/attack-on-pycrypto-elgamal"},{"type":"REPORT","url":"https://github.com/Legrandin/pycryptodome/issues/90"},{"type":"REPORT","url":"https://github.com/dlitz/pycrypto/issues/253"}],"affected":[{"package":{"name":"python-pycrypto","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/python-pycrypto?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.1-6.2.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0171.json"}},{"package":{"name":"python-pycrypto","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/python-pycrypto?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.1-9.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0171.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}