Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xrx6-fmxq-rjj2

Опубликовано: 30 апр. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.2
CVSS3: 5.9

Описание

Timing attacks in python-rsa

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA

Пакеты

Наименование

rsa

pip
Затронутые версииВерсия исправления

>= 2.1, < 4.7

4.7

EPSS

Процентиль: 46%
0.00233
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-327
CWE-385

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

CVSS3: 5.9
redhat
больше 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

CVSS3: 7.5
nvd
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

CVSS3: 7.5
debian
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing at ...

suse-cvrf
почти 3 года назад

Security update for python-rsa

EPSS

Процентиль: 46%
0.00233
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-327
CWE-385