Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-944j-8ch6-rf6x

Опубликовано: 05 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Пакеты

Наименование

m2crypto

pip
Затронутые версииВерсия исправления

<= 0.40.1

Отсутствует

EPSS

Процентиль: 53%
0.00306
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
redhat
больше 1 года назад

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
debian
больше 1 года назад

A flaw was found in m2crypto. This issue may allow a remote attacker t ...

CVSS3: 7.5
redos
около 1 года назад

Уязвимость python3-m2crypto

EPSS

Процентиль: 53%
0.00306
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-208