Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25658

Опубликовано: 09 нояб. 2020
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

A flaw was found in python-rsa, where it is vulnerable to Bleichenbacher timing attacks. This flaw allows an attacker, via the RSA decryption API, to decrypt parts of the ciphertext encrypted with RSA. The highest threat from this vulnerability is to confidentiality.

Отчет

In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-rsa package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9python-rsaAffected
Red Hat OpenStack Platform 13 (Queens)python-rsaWill not fix
Red Hat OpenStack Platform 16 (Train)python-rsaWill not fix
Red Hat Quay 3quayWill not fix
Red Hat Ceph Storage 4.3python-rsaFixedRHSA-2022:171605.05.2022
Red Hat OpenShift Container Platform 3.11python-rsaFixedRHSA-2021:063703.03.2021
Red Hat OpenShift Container Platform 4.7python-rsaFixedRHSA-2020:563424.02.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1889972python-rsa: bleichenbacher timing oracle attack against RSA decryption

EPSS

Процентиль: 46%
0.00233
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

CVSS3: 7.5
nvd
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

CVSS3: 7.5
debian
около 5 лет назад

It was found that python-rsa is vulnerable to Bleichenbacher timing at ...

suse-cvrf
почти 3 года назад

Security update for python-rsa

suse-cvrf
около 3 лет назад

Security update for python-rsa

EPSS

Процентиль: 46%
0.00233
Низкий

5.9 Medium

CVSS3