PT-2023-31051 · Openssl+1 · Openssl+1

Tomato42

·

Publicado

2023-11-22

·

Atualizado

2024-06-15

·

CVE-2023-49092

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RustCrypto/RSA (affected versions not specified)
Description The issue is due to a non-constant-time implementation, which leaks information about the private key through timing information observable over the network. An attacker may use this information to recover the key. This vulnerability was discovered as part of the "Marvin Attack", which revealed several RSA implementations, including OpenSSL, had not properly mitigated timing side-channel attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider avoiding the use of the rsa crate in settings where attackers are able to observe timing information, e.g., local use on a non-compromised computer is fine.

Exploit

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49092
GHSA-4GRX-2X9W-596C
GHSA-C38W-74PG-36HR
OPENSUSE-SU-2024:13542-1
RUSTSEC-2023-0071

Produtos afetados

Debian
Openssl