Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-52323

Опубликовано: 05 янв. 2024
Источник: redhat
CVSS3: 5.9

Описание

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

A flaw was found in PyCryptodome/pycryptodomex which may allow for side-channel leakage when performing OAEP decryption, which could be exploited to carry out a Manger attack.

Отчет

Red Hat Satellite ship affected version of pycryptodome for pulp_container, however, product is not vulnerable as it doesn't utilize OAEP algorithm technique. Red Hat Product Security has classified its impact as Low for Red Hat Satellite; future updates expected to address this issue. Red Hat OpenStack 16.1 and 16.2 versions include affected python-scciclient embedded through the python-crypto package, however, python-scciclient employs only one algorithm, which is AES. While the version of python-crypto we ship may be susceptible to a particular CVE, since affected algorithms are not utilized by OpenStack, the attack cannot be executed to exploit an OpenStack deployment

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2python3x-joseNot affected
Red Hat Ansible Automation Platform 2python-joseNot affected
Red Hat Enterprise Linux 7fence-agentsOut of support scope
Red Hat Enterprise Linux 7resource-agentsOut of support scope
Red Hat OpenShift Container Platform 4pysnmpNot affected
Red Hat OpenStack Platform 16.1python-cryptoNot affected
Red Hat OpenStack Platform 16.2python-cryptoNot affected
Red Hat OpenStack Platform 17.1pysnmpNot affected
Red Hat OpenStack Platform 18.0pysnmpNot affected
Red Hat Storage 3pysnmpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-203
https://bugzilla.redhat.com/show_bug.cgi?id=2257028pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 1 года назад

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

CVSS3: 5.9
nvd
больше 1 года назад

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

CVSS3: 5.9
debian
больше 1 года назад

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakag ...

suse-cvrf
больше 1 года назад

Security update for python-pycryptodome

suse-cvrf
больше 1 года назад

Security update for python-pycryptodome

5.9 Medium

CVSS3