CVE-2020-25658
HIGHpython-rsa 2.1-4.6 - Bleichenbacher Timing Attack via RSA Decryption API
Title source: llmDescription
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
References (5)
Core 5
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25658
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/sybrenstuvel/python-rsa/issues/165
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SAF67KDGSOHLVFTRDOHNEAFDRSSYIWA/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QY4PJWTYSOV7ZEYZVMYIF6XRU73CY6O7/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APF364QJ2IYLPDNVFBOEJ24QP2WLVLJP/
Scores
CVSS v3
7.5
EPSS
0.0014
EPSS Percentile
34.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-327
CWE-385
Status
published
Products (7)
fedoraproject/fedora
33
fedoraproject/fedora
34
fedoraproject/fedora
35
pypi/rsa
2.1 - 4.7PyPI
python-rsa_project/python-rsa
2.1 - 4.7
redhat/openstack_platform
13.0
redhat/openstack_platform
16.0
Published
Nov 12, 2020
Tracked Since
Feb 18, 2026