Skip to content

x/vulndb: potential Go vuln in github.com/pyca/cryptography: CVE-2020-25659 #430

Closed
@GoVulnBot

Description

@GoVulnBot

CVE-2020-25659 references github.com/pyca/cryptography, which may be a Go module.

Description:
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.

Links:

See doc/triage.md for instructions on how to triage this report.

module: github.com/pyca/cryptography
package: python-cryptography
description: |
    python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
cves:
  - CVE-2020-25659
links:
    commit: https://github.com/pyca/cryptography/pull/5507/commits/ce1bef6f1ee06ac497ca0c837fbd1c7ef6c2472b
    context:
      - https://www.oracle.com/security-alerts/cpuapr2022.html

Metadata

Metadata

Assignees

No one assigned

    Labels

    excluded: NOT_GO_CODEThis vulnerability does not refer to a Go module.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions