<´╗┐img height="1" width="1" style="display:none;" alt="" src="https://dc.ads.linkedin.com/collect/?pid=112631&fmt=gif" />

CVE Database

CVE-2018-10903

A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.

Priority: --
CVSS v3: 0.0
Publish Date: 2018-07-30
Related ID : --
CVSS v2: 0.0
Modified Date: 2018-07-30

Find out more about CVE-2018-10903 from the MITRE-CVE dictionary and NIST NVD

Products Affected

Login may be required to access defects or downloads.
Product Name Status Defect Fixed Downloads
Wind River Linux LTS Fixed -- 10.17.41.10 --
Wind River Linux 9 Not Vulnerable -- -- --
Wind River Linux 8 Not Vulnerable -- -- --
Wind River Linux 7 Not Vulnerable -- -- --
Wind River Linux 6 Not Vulnerable -- -- --
Wind River Linux 5 Not Vulnerable -- -- --
VxWorks 7 Not Vulnerable -- -- --
VxWorks 6.9 Not Vulnerable -- -- --
VxWorks 6.8 Not Vulnerable -- -- --
VxWorks 6.7 Not Vulnerable -- -- --
VxWorks 6.6 Not Vulnerable -- -- --
VxWorks 6.4 Not Vulnerable -- -- --
VxWorks 5.5 Not Vulnerable -- -- --

Related Products

Status Related Products
Not VulnerableLinux 5 CGP, Linux 5 OVP, Linux 6 CGP, Linux 6 SCP, Linux 7 CGP, Linux 7 SCP, Linux 8, Linux 9
Investigate
Vulnerable
FixedLinux LTS 17 (10.17.41.10)

Comments

python-cryptography