REDHAT-BUG-1889823: Medium severity m2crypto vulnerability
Published Oct 20, 2020
·Updated
All released versions of m2crypto are vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 ciphertext.
Upstream issue:
https://gitlab.com/m2crypto/m2crypto/-/issues/285
Affected Software
1 affected component
M2Crypto M2Crypto<=
Event History
Oct 20, 2020
Data Sourced
via Red Hat·04:34 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1889823?
The severity of REDHAT-BUG-1889823 is categorized as high due to the potential for timing attacks on RSA decryption.
2
How do I fix REDHAT-BUG-1889823?
To fix REDHAT-BUG-1889823, you should update to the latest version of M2Crypto that addresses the timing attack vulnerability.
3
Which versions of M2Crypto are affected by REDHAT-BUG-1889823?
All released versions of M2Crypto are affected by REDHAT-BUG-1889823.
4
What type of attack does REDHAT-BUG-1889823 involve?
REDHAT-BUG-1889823 involves Bleichenbacher timing attacks on RSA decryption.
5
Is there a workaround for REDHAT-BUG-1889823?
Currently, the recommended approach is to update M2Crypto as there is no specific workaround for REDHAT-BUG-1889823.