Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 12.04 LTS USN-1484-1 Moderate PyCrypto ElGamal Key Issue

ubuntu
Calendar Grey June 28, 2012
Scroller Ubuntu
Uncover the consequences of the PyCrypto vulnerability on ElGamal key creation in Ubuntu systems. Updates for enhanced security are now accessible.
PyCrypto improperly created ElGamal encryption keys.

Summary

PyCrypto improperly created ElGamal encryption keys.

Software Description:

- python-crypto: cryptographic algorithms and protocols for Python

Details:

It was discovered that PyCrypto produced inappropriate prime numbers when

generating ElGamal keys. An attacker could use this flaw to facilitate

brute-forcing of ElGamal encryption keys.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  python-crypto                   2.4.1-1ubuntu0.1

Ubuntu 11.10:
  python-crypto                   2.3-2ubuntu0.1

Ubuntu 11.04:
  python-crypto                   2.1.0-2ubuntu1.1

Ubuntu 10.04 LTS:
  python-crypto                   2.0.1+dfsg1-4ubuntu2.2

In general, a standard system update will make all the necessary changes.
If PyCrypto was used to generate ElGamal keys, we recommend they be
regenerated.

References

https://ubuntu.com/security/notices/USN-1484-1

CVE-2012-2417

Severity
important
Lowest
Low
Medium
High
Critical

June 28, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.