drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Erzeugung schwacher Schlüssel in PyCrypto
Name: |
Erzeugung schwacher Schlüssel in PyCrypto |
|
ID: |
USN-1484-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 10.04 LTS, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04 LTS |
|
Datum: |
Do, 28. Juni 2012, 20:56 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2417 |
|
Applikationen: |
PyCrypto |
|
Originalnachricht |
--===============8311851466769284440== Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-PRwtedQlKiV1aof1Gk/B"
--=-PRwtedQlKiV1aof1Gk/B Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-1484-1 June 28, 2012
python-crypto vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS
Summary:
PyCrypto improperly created ElGamal encryption keys.
Software Description: - python-crypto: cryptographic algorithms and protocols for Python
Details:
It was discovered that PyCrypto produced inappropriate prime numbers when generating ElGamal keys. An attacker could use this flaw to facilitate brute-forcing of ElGamal encryption keys.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 LTS: python-crypto 2.4.1-1ubuntu0.1
Ubuntu 11.10: python-crypto 2.3-2ubuntu0.1
Ubuntu 11.04: python-crypto 2.1.0-2ubuntu1.1
Ubuntu 10.04 LTS: python-crypto 2.0.1+dfsg1-4ubuntu2.2
In general, a standard system update will make all the necessary changes. If PyCrypto was used to generate ElGamal keys, we recommend they be regenerated.
References: http://www.ubuntu.com/usn/usn-1484-1 CVE-2012-2417
Package Information: https://launchpad.net/ubuntu/+source/python-crypto/2.4.1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/python-crypto/2.3-2ubuntu0.1 https://launchpad.net/ubuntu/+source/python-crypto/2.1.0-2ubuntu1.1 https://launchpad.net/ubuntu/+source/python-crypto/2.0.1+dfsg1-4ubuntu2.2
--ÙRwtedQlKiV1aof1Gk/B Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAABCgAGBQJP7KO+AAoJEGVp2FWnRL6TjCQP/1kGLm3PjBMKhIi0HFP4bzcR bwOBotKrNaJaWdSsORtCs4H2jKjHRbmi2pJaGRZlZYdAnpY6/w5Z/GqpZg2d92h+ +T+k5+MXaaQwz/RGNMGsPN8s4ViUydX26/379bx/lnmlEy6xHW7z2BX1PEMr7Mhs rRk7e0baortXDIMj3ZJmLqmvSrg50EpEM/FXCFrt3o1GVLcruXGc6xmlZmfSZ+CZ 8r9rJ8UzZAXRz1nNvjbT80wjgSlD1R6AA6UJ+30GN2aQzE0OFvGPsPP+2r+dU2KQ BkEWiU3DTxMbS5eMy7XFrX2USVTSfxN2pjqdndYtDYf7isaqqkSbLLd586t32cqT 4sEHZvO7y9FMtcTsbWk4+amgmsjnIjcH4jYwKHx6WR3/Evj13vlMBDwPsGP1/dnA 35rxoQUpLp11Vtdz3QwUsPogXKcqWNQ4fkSg0zX7Vaj4xqw3Cf0miHepLj/Bz05Z xr1Kj7Koy7OTAaOorwdZNRxT++CroYfX6xJEMZVpKXke4RbGI/X0PzXIZfDFEmSz 4dYTKDhwxtny4o7FIXqYCO+PMlflyhkB41qtscSTvch6ZiTSlkeTu/VikZqKqL0F 7f72VzGkxmucqv1iPbeI/K9AKAymgnVjfqYpJfJVnAcxT4axzBMqmJtEbQNzu6sR uaXki1bfRraxfQh5d3U1 =jUxs -----END PGP SIGNATURE-----
--=-PRwtedQlKiV1aof1Gk/B--
--===============8311851466769284440== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============8311851466769284440==--
|
|
|
|