CVE-2024-2467

EUVD-2024-27416
A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Debian logo
Debian Releases
Debian Product
Codename
libcrypt-openssl-rsa-perl
bookworm
no-dsa
bullseye
no-dsa
buster
postponed
forky
0.35-1
fixed
sid
0.35-1
fixed
trixie
0.35-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcrypt-openssl-rsa-perl
bionic
deferred
focal
deferred
jammy
deferred
mantic
ignored
noble
deferred
oracular
ignored
plucky
deferred
questing
deferred
trusty
deferred
xenial
deferred
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-Crypt-OpenSSL-RSA
Amazon Linux 2
0:0.28-7.amzn2.0.3
fixed
perl-Crypt-OpenSSL-RSA-debuginfo
Amazon Linux 2
0:0.28-7.amzn2.0.3
fixed