CVE-2020-25658
published 2020-11-12CVE-2020-25658: It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the…
medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-rsa | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| paloalto | pan-os | — | — |
| python-rsa_project | python-rsa | >= 2.1 < 4.7 | 4.7 |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| rustcrypto | rsa | >= 2.1 < 4.7 | 4.7 |
| sybren_a_st_vel | python-rsa | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM