Solution
Please Install the Updated Packages.
Insight
A vulnerability has been discovered and corrected in python-pycrypto:
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key (CVE-2012-2417).
The updated packages have been patched to correct this issue.
Affected
python-pycrypto on Mandriva Linux 2011.0,
Mandriva Enterprise Server 5.2
Severity
Classification
-
CVE CVE-2012-2417 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities