cbcvebase.
CVE-2020-25658
published 2020-11-12

CVE-2020-25658: It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the…

medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianpython-rsa
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
paloaltopan-os
python-rsa_projectpython-rsa>= 2.1 < 4.74.7
redhatopenstack_platform
redhatopenstack_platform
rustcryptorsa>= 2.1 < 4.74.7
sybren_a_st_velpython-rsa

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM