USN-6595-1: PyCryptodome vulnerability
Published Jan 23, 2024
·Updated
It was discovered that PyCryptodome had a timing side-channel when performing OAEP decryption. A remote attacker could possibly use this issue to recover sensitive information.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/python3-pycryptodome<3.11.0+dfsg1-3ubuntu0.1
3.11.0+dfsg1-3ubuntu0.1
Ubuntu Ubuntu=22.04
Event History
Jan 23, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6595-1?
The severity of USN-6595-1 is classified as a moderate security vulnerability.
2
How do I fix USN-6595-1?
To fix USN-6595-1, upgrade to python3-pycryptodome version 3.11.0+dfsg1-3ubuntu0.1 or later.
3
Who is affected by USN-6595-1?
Users of Ubuntu 22.04 with the affected version of python3-pycryptodome are vulnerable to USN-6595-1.
4
What type of vulnerability is USN-6595-1?
USN-6595-1 is a timing side-channel vulnerability related to OAEP decryption in PyCryptodome.
5
Can USN-6595-1 allow data theft?
Yes, USN-6595-1 could potentially allow a remote attacker to recover sensitive information.