VDB
GCVE-110-MAGEIA-2018-429
GCVE-110-MAGEIA-2018-429
Advisory Published
The python-cryptography and python-cryptography-vectors packages have
been updated to version 2.3.1 and fixes the following security issue:
The finalize_with_tag API did not enforce a minimum tag length. If a
user did not validate the input length prior to passing it to
finalize_with_tag an attacker could craft an invalid payload with a
shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance
of passing the MAC check. GCM tag forgeries can cause key leakage
(CVE-2018-10903).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | python-cryptography-vectors | 0 (affected), 2.3.1-1.mga6 (unaffected) | — |
| Mageia | python-cryptography | 0 (affected), 2.3.1-1.mga6 (unaffected) | — |
| Mageia | python-asn1crypto | 0 (affected), 0.22.0-1.1.mga6 (unaffected) | — |
| Mageia | python-cffi | 0 (affected), 1.7.0-1.mga6 (unaffected) | — |
Aliases
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.