Search CVE reports
11 – 15 of 15 results
CVE-2016-9243
Medium priorityHKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
1 affected packages
python-cryptography
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-cryptography | — | — | — | — | Fixed |
CVE-2013-1445
Low priorityThe Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to...
1 affected packages
python-crypto
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-crypto | — | — | Not affected | Not affected | Not affected |
CVE-2007-6755
Low priorityThe NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might...
10 affected packages
bouncycastle, gnutls26, gnutls28, libgcrypt11, mbedtls...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
bouncycastle | — | — | — | Not affected | Not affected |
gnutls26 | — | — | — | Not in release | Not in release |
gnutls28 | — | — | — | Not affected | Not affected |
libgcrypt11 | — | — | — | Not in release | Not in release |
mbedtls | — | — | — | Not affected | Not affected |
nss | — | — | — | Not affected | Not affected |
openssl | — | — | — | Not affected | Not affected |
openssl098 | — | — | — | Not in release | Not in release |
polarssl | — | — | — | Not in release | Not in release |
python-crypto | — | — | — | Not affected | Not affected |
CVE-2012-2417
Medium prioritySome fixes available 4 of 5
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks...
1 affected packages
python-crypto
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-crypto | — | — | — | — | — |
CVE-2009-0544
Medium priorityBuffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.
1 affected packages
python-crypto
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-crypto | — | — | — | — | — |