Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25659

Опубликовано: 25 окт. 2020
Источник: redhat
CVSS3: 5.9

Описание

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

A flaw was found in python-cryptography, where it is vulnerable to Bleichenbacher timing attacks. This flaw allows an attacker, via the RSA decryption API, to decrypt parts of the ciphertext encrypted with RSA. The highest threat from this vulnerability is to confidentiality.

Отчет

In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP python-cryptography package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5python-cryptographyNot affected
Red Hat Ansible Automation Platform 1.2python-cryptographyWill not fix
Red Hat Ansible Engine 2python-cryptographyOut of support scope
Red Hat Ansible Tower 3cryptographyOut of support scope
Red Hat Enterprise Linux 7python-cryptographyWill not fix
Red Hat Enterprise Linux 9python-cryptographyNot affected
Red Hat OpenStack Platform 13 (Queens)python-cryptographyWill not fix
Red Hat Enterprise Linux 8python-cryptographyFixedRHSA-2021:160818.05.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-babelFixedRHSA-2021:325424.08.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-python38-pythonFixedRHSA-2021:325424.08.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1889988python-cryptography: Bleichenbacher timing oracle attack against RSA decryption

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 4 лет назад

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

CVSS3: 5.9
nvd
больше 4 лет назад

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

CVSS3: 5.9
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 5.9
debian
больше 4 лет назад

python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks ...

suse-cvrf
больше 4 лет назад

Security update for python-cryptography

5.9 Medium

CVSS3