Oval Definition:oval:com.ubuntu.xenial:def:201810903000
Revision Date:2018-07-30Version:1
Title:CVE-2018-10903 on Ubuntu 16.04 LTS (xenial) - medium.
Description:A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-10903
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND NOT While related to the CVE in some way, the 'python-cryptography' package in xenial is not affected (note: 'code not present').
  • BACK