Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-25657

Опубликовано: 12 янв. 2021
Источник: debian

Описание

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
m2cryptofixed0.38.0-4package
m2cryptono-dsabullseyepackage
m2cryptono-dsabusterpackage
m2cryptono-dsastretchpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1889823

  • https://gitlab.com/m2crypto/m2crypto/-/issues/285

  • https://gitlab.com/m2crypto/m2crypto/-/issues/282 (restricted)

  • https://gitlab.com/m2crypto/m2crypto/-/commit/84c53958def0f510e92119fca14d74f94215827a

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 5 лет назад

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

CVSS3: 7.5
redhat
около 5 лет назад

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.9
nvd
около 5 лет назад

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

CVSS3: 5.9
msrc
больше 3 лет назад

Описание отсутствует

suse-cvrf
больше 3 лет назад

Security update for python-M2Crypto