PT-2023-31051 · Openssl+1 · Openssl+1

Tomato42

·

Published

2023-11-22

·

Updated

2024-06-15

·

CVE-2023-49092

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RustCrypto/RSA (affected versions not specified)
Description The issue is due to a non-constant-time implementation, which leaks information about the private key through timing information observable over the network. An attacker may use this information to recover the key. This vulnerability was discovered as part of the "Marvin Attack", which revealed several RSA implementations, including OpenSSL, had not properly mitigated timing side-channel attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider avoiding the use of the rsa crate in settings where attackers are able to observe timing information, e.g., local use on a non-compromised computer is fine.

Exploit

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49092
GHSA-4GRX-2X9W-596C
GHSA-C38W-74PG-36HR
OPENSUSE-SU-2024:13542-1
RUSTSEC-2023-0071

Affected Products

Debian
Openssl