PT-2020-6862 · Openssl+12 · Openssl+12

·

CVE-2022-4304

·

Published

2020-07-14

·

Updated

2026-06-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description A timing-based side channel exists in the OpenSSL RSA Decryption implementation, which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption, an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP, and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages, the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Side Channel Attack

Double Free

NULL Pointer Dereference

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2023:0946
ALSA-2023:1405
ALSA-2023:2165
ALSA-2023:2932
ALT-PU-2023-1195
ALT-PU-2023-1228
ALT-PU-2023-1299
ALT-PU-2023-1360
AZL-13302
AZL-13310
AZL-31140
AZL-34668
AZL-37662
AZL-37955
BDU:2023-00665
BDU:2023-02237
BDU:2023-02238
BDU:2023-02239
BDU:2023-02240
CESA-2023_1405
CESA-2023_2932
CVE-2022-4304
DLA-3325-1
DSA-5343-1
FREEBSD-SA-23_03
GHSA-P52G-CM5J-MJV4
JLSEC-2026-231
MGASA-2023-0130
OESA-2023-1092
OESA-2023-1107
OESA-2023-1142
OESA-2023-1428
OESA-2023-1429
OESA-2023-1430
OESA-2023-1431
OPENSUSE-SU-2023_0305-1
OPENSUSE-SU-2023_0311-1
OPENSUSE-SU-2023_0312-1
OPENSUSE-SU-2023_2633-1
OPENSUSE-SU-2024:12687-1
OPENSUSE-SU-2024:12688-1
OPENSUSE-SU-2024:12716-1
RHSA-2023:0946
RHSA-2023:1199
RHSA-2023:1405
RHSA-2023:2165
RHSA-2023:2932
RHSA-2023:3354
RHSA-2023:3408
RHSA-2023:3420
RHSA-2023:4128
RHSA-2023_0946
RHSA-2023_1405
RHSA-2023_2165
RHSA-2023_2932
RLSA-2023:0946
RLSA-2023:1405
RUSTSEC-2023-0007
SUSE-SU-2023:0305-1
SUSE-SU-2023:0305-2
SUSE-SU-2023:0306-1
SUSE-SU-2023:0307-1
SUSE-SU-2023:0308-1
SUSE-SU-2023:0309-1
SUSE-SU-2023:0310-1
SUSE-SU-2023:0311-1
SUSE-SU-2023:0312-1
SUSE-SU-2023:0581-1
SUSE-SU-2023:0584-1
SUSE-SU-2023:0684-1
SUSE-SU-2023:2622-1
SUSE-SU-2023:2623-1
SUSE-SU-2023:2624-1
SUSE-SU-2023:2633-1
SUSE-SU-2023:2634-1
SUSE-SU-2023:2648-1
SUSE-SU-2023:29171-1
SUSE-SU-2023:3096-1
SUSE-SU-2023:3179-1
SUSE-SU-2023_0305
SUSE-SU-2023_0305-1
SUSE-SU-2023_0306-1
SUSE-SU-2023_0307-1
SUSE-SU-2023_0308-1
SUSE-SU-2023_0309-1
SUSE-SU-2023_0310-1
SUSE-SU-2023_0311-1
SUSE-SU-2023_0581-1
SUSE-SU-2023_0584-1
SUSE-SU-2023_0684-1
SUSE-SU-2023_2622-1
SUSE-SU-2023_2623-1
SUSE-SU-2023_2624-1
SUSE-SU-2023_2633-1
SUSE-SU-2023_2634-1
SUSE-SU-2023_2648-1
SUSE-SU-2023_29171-1
SUSE-SU-2023_3096-1
SUSE-SU-2023_3179-1
USN-5844-1
USN-6564-1
USN-7894-1
USN-7894-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Freebsd
Ibm Aix
Linuxmint
Openssl
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu