m2crypto: bleichenbacher timing attacks in the RSA decryption API
Published Jan 12, 2021
7.5
HIGHCVSS 3.1
EPSS 1.76%
Description
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
Affected products
- Vendor n/a Product M2crypto Defaultunknown
Affected
- All released versions of m2crypto
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | M2crypto | unknown | Affected
|
Configuration 1
- n/a
Configuration 2
- 4.0
- 6.0
- 7.0
Configuration 3
- 33
No data.
Red Hat Virtualization Engine 4.4
org.ovirt.engine-root-0:4.4.5.9-1
Fixed · RHSA-2021:1169
Red Hat Enterprise Linux 6
m2crypto
Out of support scope
Red Hat Enterprise Linux 7
m2crypto
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Virtualization Engine 4.4 | org.ovirt.engine-root-0:4.4.5.9-1 | Fixed | RHSA-2021:1169 |
| Red Hat Enterprise Linux 6 | m2crypto | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | m2crypto | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2020-25657 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1889823 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-18321 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-25657
- https://www.cve.org/CVERecord?id=CVE-2020-25657
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-25657 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1889823 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-18321 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-25657 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-25657 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data