Security Advisory

CVE-2021-40529

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-09-06 18:45:08
Last updated 2024-08-04 02:44:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.