Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-50781

Опубликовано: 13 дек. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Отчет

This vulnerability exists due to an incomplete fix for CVE-2020-25657.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6m2cryptoOut of support scope
Red Hat Enterprise Linux 7m2cryptoOut of support scope
Red Hat Enterprise Linux 8virt-whoNot affected
Red Hat Enterprise Linux 9pywbemNot affected
Red Hat Enterprise Linux 9virt-whoNot affected
Red Hat Update Infrastructure 4 for Cloud Providersm2cryptoAffected
Red Hat Virtualization 4m2cryptoNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-327->CWE-385->CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2254426m2crypto: Bleichenbacher timing attacks in the RSA decryption API - incomplete fix for CVE-2020-25657

EPSS

Процентиль: 53%
0.00306
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

CVSS3: 7.5
debian
больше 1 года назад

A flaw was found in m2crypto. This issue may allow a remote attacker t ...

CVSS3: 7.5
redos
около 1 года назад

Уязвимость python3-m2crypto

CVSS3: 5.9
github
больше 1 года назад

m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657

EPSS

Процентиль: 53%
0.00306
Низкий

7.5 High

CVSS3