A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade m2crypto | Jul 30, 2024 | Jan 12, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 12, 2021 |
| Suse | — | Upgrade python-M2CryptoUpgrade python311-M2CryptoUpgrade python2-M2CryptoUpgrade python3-M2CryptoUpgrade python-M2Crypto-doc | Aug 9, 2024 | Jan 12, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub