Back

HIGH

m2crypto: bleichenbacher timing attacks in the RSA decryption API

Published Jan 12, 2021

Description

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jan 12, 2021
Updated Aug 4, 2024
Reserved Sep 16, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Nov 13, 2020
Bugzilla 1889823

ENISA EUVD

Assigner redhat
Published Jan 12, 2021
Updated Aug 4, 2024

GitHub

No data