Bug 1889823 (CVE-2020-25657) - CVE-2020-25657 m2crypto: bleichenbacher timing attacks in the RSA decryption API
Summary: CVE-2020-25657 m2crypto: bleichenbacher timing attacks in the RSA decryption API
Keywords:
Status: NEW
Alias: CVE-2020-25657
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1898305
Blocks: 1889511
TreeView+ depends on / blocked
 
Reported: 2020-10-20 16:34 UTC by Todd Cullum
Modified: 2020-11-18 02:24 UTC (History)
17 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:


Attachments (Terms of Use)

Description Todd Cullum 2020-10-20 16:34:40 UTC
All released versions of m2crypto are vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

Comment 4 Todd Cullum 2020-11-16 18:02:19 UTC
Statement:

This Moderate severity flaw is Out of Support Scope for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. To learn more about product support scopes for Red Hat Enterprise Linux, please see https://access.redhat.com/support/policy/updates/errata/ .

Comment 5 Todd Cullum 2020-11-16 18:53:48 UTC
Created m2crypto tracking bugs for this issue:

Affects: fedora-all [bug 1898305]


Note You need to log in before you can comment on or make changes to this bug.