Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-38493

Опубликовано: 20 авг. 2022
Источник: debian

Описание

Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rhonabwyfixed1.1.7-1package
rhonabwynot-affectedbullseyepackage

Примечания

  • https://github.com/babelouest/rhonabwy/commit/dd528b3aabd13863f855a68e76966e4e019fc399

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.

CVSS3: 7.5
nvd
больше 3 лет назад

Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This allows attackers to cause a Denial of Service via a crafted JWE (JSON Web Encryption) token.