First published: Sat Feb 03 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/pycrypto | <=2.6.1 | |
debian/pycryptodome | 3.9.7+dfsg1-1 3.11.0+dfsg1-4 3.20.0+dfsg-3 | |
PyCrypto | <=2.6.1 | |
Debian Debian Linux | =7.0 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =17.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6594 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2018-6594, upgrade from PyCrypto version 2.6.1 to an alternative library such as PyCryptodome or a newer version of PyCryptography.
CVE-2018-6594 affects PyCrypto versions up to and including 2.6.1 and various Debian and Ubuntu Linux distributions with specific versions.
CVE-2018-6594 allows attackers to perform ciphertext-only attacks by exploiting weak ElGamal key parameters.
Yes, CVE-2018-6594 remains a concern for users still utilizing vulnerable versions of PyCrypto.