Home CVE Database CVE-2018-10903

CVE-2018-10903

Description

A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.

Priority: MEDIUM
CVSS v3: 7.5
Publish Date: Jul 30, 2018
Related ID: --
CVSS v2: 5.0
Modified Date: Jul 30, 2018

Find out more about CVE-2018-10903 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Product Name Status Defect Fixed Downloads
Linux
Wind River Linux LTS 17 Fixed -- 10.17.41.10 --
Wind River Linux 9 Not Vulnerable -- -- --
Wind River Linux 8 Not Vulnerable -- -- --
Wind River Linux 7 Not Vulnerable -- -- --
Wind River Linux 6 Not Vulnerable -- -- --
Wind River Linux 5 Not Vulnerable -- -- --
Wind River Linux LTS 18 Fixed -- 10.17.41.10 --
VxWorks
VxWorks 7 Not Vulnerable -- -- --
VxWorks 6.9 Not Vulnerable -- -- --
VxWorks 6.8 Not Vulnerable -- -- --
VxWorks 6.7 Not Vulnerable -- -- --
VxWorks 6.6 Not Vulnerable -- -- --
VxWorks 6.4 Not Vulnerable -- -- --
VxWorks 5.5 Not Vulnerable -- -- --

Related Products

Product name Status
Linux
Linux 7 SCP Not Vulnerable
Linux 7 CGP Not Vulnerable
Linux 6 SCP Not Vulnerable
Linux 6 CGP Not Vulnerable
Linux 5 OVP Not Vulnerable
Linux 5 CGP Not Vulnerable

Comments

python-cryptography

Live chat
Online