CVE-2020-25658: High severity python3-rfc3339 vulnerability
A flaw was found in python-rsa, where it is vulnerable to Bleichenbacher timing attacks. This flaw allows an attacker, via the RSA decryption API, to decrypt parts of the ciphertext encrypted with RSA. The highest threat from this vulnerability is to confidentiality.
Other sources
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA
— GitHub
Python-rsa is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-25658?
The severity of CVE-2020-25658 is high, primarily affecting confidentiality.
How do I fix CVE-2020-25658?
To fix CVE-2020-25658, upgrade python-rsa to version 4.8 or later.
Which versions of python-rsa are affected by CVE-2020-25658?
CVE-2020-25658 affects python-rsa versions prior to 4.8, including versions 4.7 and below.
What type of attack does CVE-2020-25658 enable?
CVE-2020-25658 enables Bleichenbacher timing attacks which can decrypt parts of RSA encrypted ciphertext.
Is CVE-2020-25658 specific to certain platforms?
CVE-2020-25658 affects python-rsa across various platforms including Red Hat OpenStack and Fedora.