Oval Definition:oval:com.ubuntu.bionic:def:201810903000
Revision Date:2018-07-30Version:1
Title:CVE-2018-10903 on Ubuntu 18.04 LTS (bionic) - medium.
Description:A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-10903
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND The 'python-cryptography' package in bionic was vulnerable but has been fixed (note: '2.1.4-1ubuntu1.2').
  • BACK