VDB

GCVE-110-MAGEIA-2018-429

GCVE-110-MAGEIA-2018-429
Advisory Published
Vulnetix · Advisory published November 3, 2018
The python-cryptography and python-cryptography-vectors packages have been updated to version 2.3.1 and fixes the following security issue: The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passing the MAC check. GCM tag forgeries can cause key leakage (CVE-2018-10903).

Affected Products

VendorProductVersionsPlatforms
Mageiapython-cryptography-vectors0 (affected), 2.3.1-1.mga6 (unaffected)
Mageiapython-cryptography0 (affected), 2.3.1-1.mga6 (unaffected)
Mageiapython-asn1crypto0 (affected), 0.22.0-1.1.mga6 (unaffected)
Mageiapython-cffi0 (affected), 1.7.0-1.mga6 (unaffected)

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›