mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
22 lines
1018 B
Markdown
22 lines
1018 B
Markdown
### [CVE-2018-6594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6594)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for PyCrypto's ElGamal implementation.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/dlitz/pycrypto/issues/253
|
|
- https://github.com/dlitz/pycrypto/issues/253
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/fincham/ssh-to-pgp
|
|
- https://github.com/jakhax/pass_cli
|
|
- https://github.com/royhershkovitz/versions_vulnerability_test
|
|
|