CVE-2020-25657
published 2021-01-12CVE-2020-25657: A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.73%
75.0th percentile
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | m2crypto | < m2crypto 0.38.0-4 (bookworm) | m2crypto 0.38.0-4 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | azl3_m2crypto_0.38.0-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_m2crypto_0.38.0-4_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_m2crypto_0.38.0-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_m2crypto_0.35.2-8_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
m2crypto: Bleichenbacher timing attacks in the RSA decryption API - incomplete fix for CVE-2020-25657
vendor_redhat·2023-12-13·CVSS 5.9
CVE-2023-50781 [MEDIUM] CWE-203 m2crypto: Bleichenbacher timing attacks in the RSA decryption API - incomplete fix for CVE-2020-25657
m2crypto: Bleichenbacher timing attacks in the RSA decryption API - incomplete fix for CVE-2020-25657
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Statement: This vulnerability exists due to an incomplete fix for CVE-2020-25657.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to wid
Microsoft
A flaw was found in all released versions of m2crypto where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The
vendor_msrc·2021-01-12·CVSS 5.9
CVE-2020-25657 [MEDIUM] CWE-385 A flaw was found in all released versions of m2crypto where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The
A flaw was found in all released versions of m2crypto where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If i
Red Hat
m2crypto: bleichenbacher timing attacks in the RSA decryption API
vendor_redhat·2020-11-13·CVSS 5.9
CVE-2020-25657 [MEDIUM] CWE-203 m2crypto: bleichenbacher timing attacks in the RSA decryption API
m2crypto: bleichenbacher timing attacks in the RSA decryption API
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
Package: m2crypto (Red Hat Enterprise Linux 6) - Out of support scope
Package: m2crypto (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2020-25657: m2crypto - A flaw was found in all released versions of m2crypto, where they are vulnerable...
vendor_debian·2020·CVSS 5.9
CVE-2020-25657 [MEDIUM] CVE-2020-25657: m2crypto - A flaw was found in all released versions of m2crypto, where they are vulnerable...
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
Scope: local
bookworm: resolved (fixed in 0.38.0-4)
bullseye: open
trixie: resolved (fixed in 0.38.0-4)
OSV
m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
osv·2024-02-05·CVSS 5.9
CVE-2023-50781 [MEDIUM] m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
GHSA
m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
ghsa·2024-02-05·CVSS 5.9
CVE-2023-50781 [MEDIUM] CWE-203 m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
m2crypto Bleichenbacher timing attack - incomplete fix for CVE-2020-25657
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
GHSA
GHSA-2j9v-8g47-mxh2: A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the ti
ghsa_unreviewed·2022-05-24
CVE-2020-25657 [MEDIUM] CWE-203 GHSA-2j9v-8g47-mxh2: A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the ti
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
OSV
CVE-2020-25657: A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the ti
osv·2021-01-12·CVSS 5.9
CVE-2020-25657 [MEDIUM] CVE-2020-25657: A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the ti
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25657 m2crypto: bleichenbacher timing attacks in the RSA decryption API
bugzilla·2020-10-20·CVSS 5.9
CVE-2020-25657 [MEDIUM] CVE-2020-25657 m2crypto: bleichenbacher timing attacks in the RSA decryption API
CVE-2020-25657 m2crypto: bleichenbacher timing attacks in the RSA decryption API
All released versions of m2crypto are vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
Upstream issue:
https://gitlab.com/m2crypto/m2crypto/-/issues/285
Discussion:
Created m2crypto tracking bugs for this issue:
Affects: fedora-all [bug 1898305]
---
This issue has been addressed in the following products:
Red Hat Virtualization Engine 4.4
Via RHSA-2021:1169 https://access.redhat.com/errata/RHSA-2021:1169
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-25657
---
In the end we have decided to close this with https://gi
Bleepingcomputer
New Marvin attack revives 25-year-old decryption flaw in RSA
blogs_bleepingcomputer·2023-10-01·CVSS 5.9
[MEDIUM] New Marvin attack revives 25-year-old decryption flaw in RSA
## New Marvin attack revives 25-year-old decryption flaw in RSA
## Bill Toulas
A flaw related to the PKCS #1 v1.5 padding in SSL servers discovered in 1998 and believed to have been resolved still impacts several widely-used projects today.
After extensive testing that measures end-to-end operations, Red Hat researchers discovered several variations of the original timing attack, collectively called the 'Marvin Attack,' which can effectively bypass fixes and mitigations.
The problem allows attackers to potentially decrypt RSA ciphertexts, forge signatures, and even decrypt sessions recorded on a vulnerable TLS server.
Using standard hardware, the researchers demonstrated that executing the Marvin Attack within just a couple of hours is possible, proving its practicality.
Red Hat warn
2021-01-12
Published