
We found results for “”
CVE-2020-25659
Good to know:


Date: January 11, 2021
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
Language: Python
Severity Score
Related Resources (13)
Severity Score
Weakness Type (CWE)
Covert Timing Channel
CWE-385Top Fix

Upgrade Version
Upgrade to version pypy3.7 - no_fix;dbxfs - 1.0.41;cryptography - 3.2;ovmf - no_fix;pypy3.6 - no_fix;wakatime - no_fix;privy - no_fix;pypy3.8 - 7.3.8;cryptography - 3.2
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | NONE |
Availability (A): | NONE |
Additional information: |