Fedora Account System
Red Hat Associate
Red Hat Customer
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP. References: https://ibm.github.io/system-security-research-updates/2021/07/20/insecurity-elgamal-pt1 https://ibm.github.io/system-security-research-updates/2021/09/06/insecurity-elgamal-pt2 https://eprint.iacr.org/2021/923 Upstream patch: https://github.com/randombit/botan/pull/2790
Created botan tracking bugs for this issue: Affects: epel-7 [bug 2002828] Affects: fedora-all [bug 2002826] Created botan2 tracking bugs for this issue: Affects: epel-8 [bug 2002829] Affects: fedora-all [bug 2002827]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.