CVE-2020-13757

Severity
7.5HIGH
EPSS
0.1%
top 73.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 1
Latest updateFeb 21

Description

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianpython-rsa< 4.7.2-1+2
PyPIrsa< 4.1

Also affects: Fedora 31, 32, Ubuntu Linux 14.04

🔴Vulnerability Details

4
GHSA
Python-RSA decryption of ciphertext leads to DoS2021-03-24
OSV
Python-RSA decryption of ciphertext leads to DoS2021-03-24
CVEList
CVE-2020-13757: Python-RSA before 42020-06-01
OSV
CVE-2020-13757: Python-RSA before 42020-06-01

📋Vendor Advisories

4
Ubuntu
Python-RSA vulnerability2022-02-21
Ubuntu
Python-RSA vulnerability2020-08-31
Red Hat
python-rsa: decryption of ciphertext leads to DoS2020-05-27
Debian
CVE-2020-13757: python-rsa - Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext...2020

💬Community

4
Bugzilla
CVE-2020-13757 python-rsa: decryption of ciphertext leads to DoS [openstack-rdo]2020-06-25
Bugzilla
CVE-2020-13757 python-rsa: decryption of ciphertext leads to DoS [epel-all]2020-06-18
Bugzilla
CVE-2020-13757 python-rsa: decryption of ciphertext leads to DoS2020-06-18
Bugzilla
CVE-2020-13757 python-rsa: decryption of ciphertext leads to DoS [fedora-all]2020-06-18
CVE-2020-13757 (HIGH CVSS 7.5) | Python-RSA before 4.1 ignores leadi | cvebase.io