CVE-2020-13757
01.06.2020, 19:15
Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).Enginsight
Vendor | Product | Version |
---|---|---|
python-rsa_project | python-rsa | 𝑥 < 4.1 |
canonical | ubuntu_linux | 14.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python-rsa |
|
Common Weakness Enumeration
References