PT-2020-13658 · Python+5 · Python-Rsa+5
Adelapie
·
Published
2020-05-27
·
Updated
2024-07-12
·
CVE-2020-13757
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Python-RSA versions prior to 4.1
Description
The issue concerns the decryption of ciphertext, where leading '0' bytes are ignored. This could potentially have security implications, such as helping an attacker infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior, like causing excessive memory allocation.
Recommendations
For versions prior to 4.1, update to version 4.1 or later to resolve the issue.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Python-Rsa
Suse
Ubuntu