CVE-2020-25657
12.01.2021, 15:15
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| m2crypto_project | m2crypto | * |
| redhat | virtualization | 4.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python-M2Crypto |
| ||||||||||||||||||||||||
| python-M2Crypto-doc |
| ||||||||||||||||||||||||
| python2-M2Crypto |
| ||||||||||||||||||||||||
| python3-M2Crypto |
| ||||||||||||||||||||||||
| python311-M2Crypto |
|
Common Weakness Enumeration