Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f8vm-23j7-pf2r

Опубликовано: 23 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.

EPSS

Процентиль: 39%
0.00175
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 5.9
nvd
около 2 лет назад

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.

EPSS

Процентиль: 39%
0.00175
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-203