PT-2016-6819 · None · Jwcrypto

Dennis Detering

·

Published

2016-09-01

·

Updated

2024-11-01

·

CVE-2016-6298

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions jwcrypto versions prior to 0.3.2
Description The issue concerns the RSA 1.5 algorithm implementation in jwa.py, which lacks the Random Filling protection mechanism. This makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).
Recommendations For versions prior to 0.3.2, update to version 0.3.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the RSA 1.5 algorithm implementation until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2016-6298
GHSA-WG33-X934-3GHH
PYSEC-2016-4

Affected Products

Jwcrypto