PyCrypto: Weak key generation A flaw in PyCrypto allow remote attackers to obtain sensitive information. pycrypto 2020-07-31 2020-07-31 703682 remote 2.6.1-r2

PyCrypto is the Python Cryptography Toolkit.

It was discovered that PyCrypto incorrectly generated ElGamal key parameters.

Attackers may be able to obtain sensitive information by reading ciphertext data.

There is no known workaround at this time.

Gentoo has discontinued support for PyCrypto. We recommend that users unmerge PyCrypto:

# emerge --unmerge “dev-python/pycrypto”

NOTE: The Gentoo developer(s) maintaining PyCrypto have discontinued support at this time. PyCryptodome is the canonical successor to PyCrypto.

CVE-2018-6594 sam_c sam_c