CVE-2024-0914

5.9MEDIUM

A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext

Опубликовано: 1/31/2024Обновлено: 11/21/2024

Описание

A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.

ИИ-АнализНа базе ИИ

Затронутые продукты

opencryptoki_projectopencryptoki
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0

Ссылки