Количество 2
Количество 2

CVE-2020-14967
An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0' bytes to ciphertexts (it decrypts modified ciphertexts without error). An attacker might prepend these bytes with the goal of triggering memory corruption issues.
GHSA-xxxq-chmp-67g4
RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2020-14967 An issue was discovered in the jsrsasign package before 8.0.18 for Node.js. Its RSA PKCS1 v1.5 decryption implementation does not detect ciphertext modification by prepending '\0' bytes to ciphertexts (it decrypts modified ciphertexts without error). An attacker might prepend these bytes with the goal of triggering memory corruption issues. | CVSS3: 9.8 | 1% Низкий | почти 5 лет назад |
GHSA-xxxq-chmp-67g4 RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign | CVSS3: 9.8 | 1% Низкий | почти 5 лет назад |
Уязвимостей на страницу