Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 84

Количество 84

ubuntu логотип

CVE-2022-4304

больше 3 лет назад

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2022-4304

больше 3 лет назад

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2022-4304

больше 3 лет назад

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
EPSS: Средний
msrc логотип

CVE-2022-4304

10 месяцев назад

Timing Oracle in RSA Decryption

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2022-4304

больше 3 лет назад

A timing based side channel exists in the OpenSSL RSA Decryption imple ...

CVSS3: 5.9
EPSS: Средний
redos логотип

ROS-20230620-06

больше 3 лет назад

Множественные уязвимости python3-cryptography

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-r7jw-wp68-3xch

больше 3 лет назад

openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2648-1

больше 3 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2634-1

больше 3 лет назад

Security update for openssl

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2633-1

больше 3 лет назад

Security update for openssl-1_0_0

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2624-1

больше 3 лет назад

Security update for openssl-1_0_0

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2623-1

больше 3 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2622-1

больше 3 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:0584-1

больше 3 лет назад

Security update for openssl

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:0581-1

больше 3 лет назад

Security update for compat-openssl098

EPSS: Средний
github логотип

GHSA-p52g-cm5j-mjv4

больше 3 лет назад

openssl-src subject to Timing Oracle in RSA Decryption

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2023-02237

около 6 лет назад

Уязвимость алгоритмов шифрования PKCS#1 v1.5, RSA-OEAP и RSASVE криптографической библиотеки OpenSSL, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher)

CVSS3: 5.9
EPSS: Средний
altlinux логотип

ALT-PU-2023-4398

около 3 лет назад

ALT-PU-2023-4398: package `LibreSSL` update to version 3.7.3-alt1

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2024-2511

больше 2 лет назад

ALT-PU-2024-2511: package `python3` update to version 3.9.18-alt1

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3179-1

около 3 лет назад

Security update for openssl-1_1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
16%
Средний
больше 3 лет назад
redhat логотип
CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
16%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
16%
Средний
больше 3 лет назад
msrc логотип
CVE-2022-4304

Timing Oracle in RSA Decryption

CVSS3: 5.9
16%
Средний
10 месяцев назад
debian логотип
CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption imple ...

CVSS3: 5.9
16%
Средний
больше 3 лет назад
redos логотип
ROS-20230620-06

Множественные уязвимости python3-cryptography

CVSS3: 9.1
больше 3 лет назад
github логотип
GHSA-r7jw-wp68-3xch

openssl-src vulnerable to Use-after-free following `BIO_new_NDEF`

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2648-1

Security update for openssl-1_1

16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2634-1

Security update for openssl

16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2633-1

Security update for openssl-1_0_0

16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2624-1

Security update for openssl-1_0_0

16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2623-1

Security update for openssl-1_1

16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2622-1

Security update for openssl-1_1

16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0584-1

Security update for openssl

16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0581-1

Security update for compat-openssl098

16%
Средний
больше 3 лет назад
github логотип
GHSA-p52g-cm5j-mjv4

openssl-src subject to Timing Oracle in RSA Decryption

CVSS3: 5.9
16%
Средний
больше 3 лет назад
fstec логотип
BDU:2023-02237

Уязвимость алгоритмов шифрования PKCS#1 v1.5, RSA-OEAP и RSASVE криптографической библиотеки OpenSSL, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher)

CVSS3: 5.9
16%
Средний
около 6 лет назад
altlinux логотип
ALT-PU-2023-4398

ALT-PU-2023-4398: package `LibreSSL` update to version 3.7.3-alt1

CVSS3: 9.8
около 3 лет назад
altlinux логотип
ALT-PU-2024-2511

ALT-PU-2024-2511: package `python3` update to version 3.9.18-alt1

CVSS3: 9.8
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3179-1

Security update for openssl-1_1

около 3 лет назад

Уязвимостей на страницу