CVE-2023-52323
published 2024-01-05CVE-2023-52323: PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.62%
46.0th percentile
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pycryptodome | < pycryptodome 3.20.0+dfsg-1 (forky) | pycryptodome 3.20.0+dfsg-1 (forky) |
| pycryptodome | pycryptodome | < 3.19.1 | 3.19.1 |
| pycryptodome | pycryptodome | >= 0 < 3.20.0+dfsg-1 | 3.20.0+dfsg-1 |
| pycryptodome | pycryptodome | >= 0 < 3.20.0+dfsg-1 | 3.20.0+dfsg-1 |
| pycryptodome | pycryptodome | >= 0 < 3.19.1 | 3.19.1 |
| pycryptodome | pycryptodomex | < 3.19.1 | 3.19.1 |
| pycryptodome | pycryptodomex | >= 0 < 3.19.1 | 3.19.1 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-52323: PyCryptodome and pycryptodomex before 3
osv·2024-01-05·CVSS 5.9
CVE-2023-52323 [MEDIUM] CVE-2023-52323: PyCryptodome and pycryptodomex before 3
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
GHSA
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
ghsa·2024-01-05
CVE-2023-52323 [HIGH] CWE-203 PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
OSV
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
osv·2024-01-05
CVE-2023-52323 [HIGH] PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
Ubuntu
PyCryptodome vulnerability
vendor_ubuntu·2024-01-23
CVE-2023-52323 PyCryptodome vulnerability
Title: PyCryptodome vulnerability
Summary: PyCryptodome could be made to expose sensitive information.
It was discovered that PyCryptodome had a timing side-channel when
performing OAEP decryption. A remote attacker could possibly use this issue
to recover sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex
vendor_redhat·2024-01-05·CVSS 5.9
CVE-2023-52323 [MEDIUM] CWE-203 pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex
pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
A flaw was found in PyCryptodome/pycryptodomex which may allow for side-channel leakage when performing OAEP decryption, which could be exploited to carry out a Manger attack.
Statement: Red Hat Satellite ship affected version of pycryptodome for pulp_container, however, product is not vulnerable as it doesn't utilize OAEP algorithm technique. Red Hat Product Security has classified its impact as Low for Red Hat Satellite; future updates expected to address this issue.
Red Hat OpenStack 16.1 and 16.2 versions include affected python-scciclient embedded through the python-cryp
Debian
CVE-2023-52323: pycryptodome - PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP...
vendor_debian·2023·CVSS 5.9
CVE-2023-52323 [MEDIUM] CVE-2023-52323: pycryptodome - PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP...
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.20.0+dfsg-1)
sid: resolved (fixed in 3.20.0+dfsg-1)
trixie: resolved (fixed in 3.20.0+dfsg-1)
No detection rules found.
No public exploits indexed.
2024-01-05
Published