Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-26939

Опубликовано: 02 нояб. 2020
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 5.3

Описание

In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

1.61-1
esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

DNE

focal

not-affected

1.61-1
groovy

not-affected

Показывать по

EPSS

Процентиль: 85%
0.02577
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs in org.bouncycastle.crypto.encodings.OAEPEncoding. Sending invalid ciphertext that decrypts to a short payload in the OAEP Decoder could result in the throwing of an early exception, potentially leaking some information about the private exponent of the RSA private key performing the encryption.

CVSS3: 5.3
debian
больше 5 лет назад

In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1. ...

CVSS3: 5.3
github
почти 5 лет назад

Observable Differences in Behavior to Error Inputs in Bouncy Castle

EPSS

Процентиль: 85%
0.02577
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3

Уязвимость CVE-2020-26939