VulnerabilityModified
CVE-2004-2721
The CheckGroup function in openSkat VTMF before 2.1 generates public key pairs in which the "p" variable might not be prime, which allows remote attackers to determine the private key and decrypt messages.
MEDIUM 4.3EPSS 1.67%
Does this matter?
Lower severity and a low EPSS score (1.67%). Track it; it rarely justifies an emergency change on its own.
Description
The CheckGroup function in openSkat VTMF before 2.1 generates public key pairs in which the "p" variable might not be prime, which allows remote attackers to determine the private key and decrypt messages.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.67% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- heiko stamer/openskat
- Source
- cve@mitre.org
References
- http://freshmeat.net/projects/openskat/?branch_id=36295&release_id=178549Patch
- http://securitytracker.com/id?1012181
- http://www.osvdb.org/11652
- http://www.securityfocus.com/bid/11667Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18049
- http://freshmeat.net/projects/openskat/?branch_id=36295&release_id=178549Patch
- http://securitytracker.com/id?1012181
- http://www.osvdb.org/11652
- http://www.securityfocus.com/bid/11667Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18049
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.