VDB
CVE-2018-10903
CVE-2018-10903
PUBLISHED
A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage.
EPSS 3.20% · 86.9th percentile
Risk Scores
EPSS Score
3.20%
86.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | python-cryptography | 0, 1.9-1, 2.1.3-3 |
Timeline
- Jul 20, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-10903 third-party-advisory
- https://ubuntu.com/security/notices/USN-3720-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-10903 third-party-advisory