PT-2020-6862 · Openssl+12 · Openssl+12

Dmitry Belyavsky

+1

·

Published

2020-07-14

·

Updated

2026-05-21

·

CVE-2022-4304

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description A timing-based side channel exists in the OpenSSL RSA Decryption implementation, which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption, an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP, and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages, the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Double Free

NULL Pointer Dereference

Side Channel Attack

Incorrect Type Conversion or Cast

Related Identifiers

ALSA-2023:0946
ALSA-2023:1405
ALSA-2023:2165
ALSA-2023:2932
ALT-PU-2023-1195
ALT-PU-2023-1228
ALT-PU-2023-1299
ALT-PU-2023-1360
AZL-13302
AZL-13310
AZL-31140
AZL-34668
AZL-37662
AZL-37955
BDU:2023-00665
BDU:2023-02237
BDU:2023-02238
BDU:2023-02239
BDU:2023-02240
CESA-2023_1405
CESA-2023_2932
CVE-2022-4304
DLA-3325-1
DSA-5343-1
FREEBSD-SA-23_03
GHSA-P52G-CM5J-MJV4
JLSEC-2026-231
MGASA-2023-0130
OESA-2023-1092
OESA-2023-1107
OESA-2023-1142
OESA-2023-1428
OESA-2023-1429
OESA-2023-1430
OESA-2023-1431
OPENSUSE-SU-2023_0305-1
OPENSUSE-SU-2023_0311-1
OPENSUSE-SU-2023_0312-1
OPENSUSE-SU-2023_2633-1
OPENSUSE-SU-2024:12687-1
OPENSUSE-SU-2024:12688-1
OPENSUSE-SU-2024:12716-1
RHSA-2023:0946
RHSA-2023:1199
RHSA-2023:1405
RHSA-2023:2165
RHSA-2023:2932
RHSA-2023:3354
RHSA-2023:3408
RHSA-2023:3420
RHSA-2023:4128
RHSA-2023_0946
RHSA-2023_1405
RHSA-2023_2165
RHSA-2023_2932
RLSA-2023:0946
RLSA-2023:1405
RUSTSEC-2023-0007
SUSE-SU-2023:0305-1
SUSE-SU-2023:0305-2
SUSE-SU-2023:0306-1
SUSE-SU-2023:0307-1
SUSE-SU-2023:0308-1
SUSE-SU-2023:0309-1
SUSE-SU-2023:0310-1
SUSE-SU-2023:0311-1
SUSE-SU-2023:0312-1
SUSE-SU-2023:0581-1
SUSE-SU-2023:0584-1
SUSE-SU-2023:0684-1
SUSE-SU-2023:2622-1
SUSE-SU-2023:2623-1
SUSE-SU-2023:2624-1
SUSE-SU-2023:2633-1
SUSE-SU-2023:2634-1
SUSE-SU-2023:2648-1
SUSE-SU-2023:29171-1
SUSE-SU-2023:3096-1
SUSE-SU-2023:3179-1
SUSE-SU-2023_0305
SUSE-SU-2023_0305-1
SUSE-SU-2023_0306-1
SUSE-SU-2023_0307-1
SUSE-SU-2023_0308-1
SUSE-SU-2023_0309-1
SUSE-SU-2023_0310-1
SUSE-SU-2023_0311-1
SUSE-SU-2023_0581-1
SUSE-SU-2023_0584-1
SUSE-SU-2023_0684-1
SUSE-SU-2023_2622-1
SUSE-SU-2023_2623-1
SUSE-SU-2023_2624-1
SUSE-SU-2023_2633-1
SUSE-SU-2023_2634-1
SUSE-SU-2023_2648-1
SUSE-SU-2023_29171-1
SUSE-SU-2023_3096-1
SUSE-SU-2023_3179-1
USN-5844-1
USN-6564-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Freebsd
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu