Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13757

Опубликовано: 27 мая 2020
Источник: redhat
CVSS3: 7.5

Описание

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).

A flaw was found in the python-rsa package, where it does not explicitly check the ciphertext length against the key size and ignores the leading 0 bytes during the decryption of the ciphertext. This flaw allows an attacker to perform a ciphertext attack, leading to a denial of service. The highest threat from this vulnerability is to confidentiality.

Отчет

In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-rsa package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 4python-rsaAffected
Red Hat OpenStack Platform 13 (Queens)python-rsaWill not fix
Red Hat OpenStack Platform 15 (Stein)python-rsaWill not fix
Red Hat OpenStack Platform 16 (Train)python-rsaWill not fix
Red Hat Quay 3python-rsaAffected
Red Hat OpenShift Container Platform 3.11python-rsaFixedRHSA-2020:354127.08.2020
Red Hat OpenShift Container Platform 4.5python-rsaFixedRHSA-2020:345318.08.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400->CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=1848507python-rsa: decryption of ciphertext leads to DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).

CVSS3: 7.5
nvd
больше 5 лет назад

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).

CVSS3: 7.5
debian
больше 5 лет назад

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ...

suse-cvrf
больше 4 лет назад

Security update for python-rsa

suse-cvrf
больше 4 лет назад

Security update for python-rsa

7.5 High

CVSS3