Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-25658

Опубликовано: 12 нояб. 2020
Источник: nvd
CVSS3: 7.5
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python-rsa_project:python-rsa:*:*:*:*:*:*:*:*
Версия от 2.1 (включая) до 4.7 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:openstack_platform:13.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack_platform:16.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

EPSS

Процентиль: 46%
0.00233
Низкий

7.5 High

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-385
CWE-327

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

CVSS3: 5.9
redhat
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

CVSS3: 7.5
debian
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing at ...

suse-cvrf
почти 3 года назад

Security update for python-rsa

suse-cvrf
около 3 лет назад

Security update for python-rsa

EPSS

Процентиль: 46%
0.00233
Низкий

7.5 High

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-385
CWE-327