CVE-2023-52323: Medium severity PyCryptodome Pycryptodome Python vulnerability
Published Jan 5, 2024
·Updated
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
Affected Software
9 affected componentsFixes available
debian/pycryptodome<=3.6.1-2, <=3.9.7+dfsg1-1, <=3.11.0+dfsg1-4, <=3.20.0+dfsg-1
ubuntu/pycryptodome<3.11.0+dfsg1-3ubuntu0.1
3.11.0+dfsg1-3ubuntu0.1
pip/pycryptodome<3.19.1
3.19.1
pip/pycryptodomex<3.19.1
3.19.1
PyCryptodome Pycryptodome Python<3.19.1
PyCryptodome Pycryptodomex Python<3.19.1
redhat/pycryptodome<3.19.1
3.19.1
IBM MQ Operator<=SC2: v3.2.0 - v3.2.13
CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.6.0
LTS: v2.0.0 - 2.0.29
IBM supplied MQ Advanced container images<=SC2: 9.4.0.6-r1, 9.4.0.6-r2, 9.4.0.7-r1, 9.4.0.10-r1, 9.4.0.10-r2, 9.4.0.11-r1, 9.4.0.11-r2, 9.4.0.11-r3CD: 9.4.1.0-r1, 9.4.1.0-r2, 9.4.1.1-r1, 9.4.2.0-r1, 9.4.2.0-r2, 9.4.2.1-r1, 9.4.2.1-r2, 9.4.3.0-r1LTS: 9.3.0.0-r1, 9.3.0.0-r2, 9.3.0.0-r3, 9.3.0.1-r1, 9.3.0.1-r2, 9.3.0.1-r3, 9.3.0.1-r4, 9.3.0.3-r1, 9.3.0.4-r1, 9.3.0.4-r2, 9.3.0.5-r1, 9.3.0.5-r2, 9.3.0.5-r3, 9.3.0.6-r1, 9.3.0.10-r1, 9.3.0.10-r2, 9.3.0.11-r1,9.3.0.11-r2, 9.3.0.15-r1, 9.3.0.16-r1, 9.3.0.16-r2, 9.3.0.17-r1, 9.3.0.17-r2, 9.3.0.17-r3, 9.3.0.20-r1, 9.3.0.20-r2, 9.3.0.21-r1, 9.3.0.21-r2, 9.3.0.21-r3, 9.3.0.25-r1, 9.4.0.0-r1, 9.4.0.0-r2, 9.4.0.0-r3, 9.4.0.5-r1, 9.4.0.5-r2
Remediation
Event History
Jan 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·06:30 AM
Jan 6, 2024
Data Sourced
via Red Hat·06:13 AM
DescriptionSeverityAffected Software
Jan 27, 2024
Data Sourced
via Launchpad·04:35 PM
Description
Jul 23, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52323?
CVE-2023-52323 is rated as a high severity vulnerability due to its potential for side-channel attacks on OAEP decryption.
2
How do I fix CVE-2023-52323?
To fix CVE-2023-52323, upgrade PyCryptodome and pycryptodomex to version 3.19.1 or later.
3
What versions are affected by CVE-2023-52323?
CVE-2023-52323 affects all versions of PyCryptodome and pycryptodomex prior to 3.19.1.
4
What types of attacks can exploit CVE-2023-52323?
CVE-2023-52323 can be exploited through a Manger attack that takes advantage of side-channel leakage during OAEP decryption.
5
Is there a recommended action for users of PyCryptodome or pycryptodomex regarding CVE-2023-52323?
Users of PyCryptodome or pycryptodomex should immediately upgrade to version 3.19.1 to mitigate the risks associated with CVE-2023-52323.