CVE-2020-25658
MEDIUM5.9EPSS 0.14%Timing attacks in python-rsa
Published: 4/30/2021Modified: 4/28/2026
Description
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.
Affected packages (3)
- Debian/python-rsafrom 0
- PyPI/rsa>= 2.1, < 4.7
- PyPI/rsa>= 2.1, < 4.7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
References (19)
- ADVISORYhttps://github.com/advisories/GHSA-xrx6-fmxq-rjj2
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-25658
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-25658
- PATCHhttps://github.com/sybrenstuvel/python-rsa
- WEBhttps://access.redhat.com/errata/RHSA-2020:5634
- WEBhttps://access.redhat.com/errata/RHSA-2021:0637
- WEBhttps://access.redhat.com/errata/RHSA-2022:1716
- WEBhttps://access.redhat.com/security/cve/CVE-2020-25658
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=1889972
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25658
- WEBhttps://github.com/pypa/advisory-database/tree/main/vulns/rsa/PYSEC-2020-100.yaml
- WEBhttps://github.com/sybrenstuvel/python-rsa/commit/dae8ce0d85478e16f2368b2341632775313d41ed
- WEBhttps://github.com/sybrenstuvel/python-rsa/issues/165
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SAF67KDGSOHLVFTRDOHNEAFDRSSYIWA
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APF364QJ2IYLPDNVFBOEJ24QP2WLVLJP
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QY4PJWTYSOV7ZEYZVMYIF6XRU73CY6O7
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/2SAF67KDGSOHLVFTRDOHNEAFDRSSYIWA
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/APF364QJ2IYLPDNVFBOEJ24QP2WLVLJP
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/QY4PJWTYSOV7ZEYZVMYIF6XRU73CY6O7