{"id":"PYSEC-2018-97","details":"lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.","aliases":["CVE-2018-6594","GHSA-6528-wvf6-f6qg"],"modified":"2023-11-08T04:00:21.756085Z","published":"2018-02-03T15:29:00Z","references":[{"type":"WEB","url":"https://github.com/TElgamal/attack-on-pycrypto-elgamal"},{"type":"REPORT","url":"https://github.com/dlitz/pycrypto/issues/253"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2018/02/msg00018.html"},{"type":"WEB","url":"https://usn.ubuntu.com/3616-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/3616-2/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202007-62"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6528-wvf6-f6qg"}],"affected":[{"package":{"name":"pycrypto","ecosystem":"PyPI","purl":"pkg:pypi/pycrypto"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9a2","1.9a5","1.9a6","2.0","2.0.1","2.1.0","2.2","2.3","2.4","2.4.1","2.5","2.6","2.6.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pycrypto/PYSEC-2018-97.yaml"}}],"schema_version":"1.7.3"}