Описание
Timing attacks in python-rsa
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-25658
- https://github.com/sybrenstuvel/python-rsa/issues/165
- https://github.com/sybrenstuvel/python-rsa/commit/dae8ce0d85478e16f2368b2341632775313d41ed
- https://access.redhat.com/security/cve/CVE-2020-25658
- https://bugzilla.redhat.com/show_bug.cgi?id=1889972
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25658
- https://github.com/advisories/GHSA-xrx6-fmxq-rjj2
- https://github.com/pypa/advisory-database/tree/main/vulns/rsa/PYSEC-2020-100.yaml
- https://access.redhat.com/errata/RHSA-2022:1716
- https://access.redhat.com/errata/RHSA-2021:0637
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SAF67KDGSOHLVFTRDOHNEAFDRSSYIWA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APF364QJ2IYLPDNVFBOEJ24QP2WLVLJP
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QY4PJWTYSOV7ZEYZVMYIF6XRU73CY6O7
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2SAF67KDGSOHLVFTRDOHNEAFDRSSYIWA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APF364QJ2IYLPDNVFBOEJ24QP2WLVLJP
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QY4PJWTYSOV7ZEYZVMYIF6XRU73CY6O7
- https://access.redhat.com/errata/RHSA-2020:5634
Пакеты
rsa
>= 2.1, < 4.7
4.7
EPSS
8.2 High
CVSS4
5.9 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
It was found that python-rsa is vulnerable to Bleichenbacher timing at ...
EPSS
8.2 High
CVSS4
5.9 Medium
CVSS3