Logo
vulnerabilityCVE-2023-50781
Name
CVE-2023-50781
Source
NVD ( link)Debian ( link)
Description
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
openssl
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.5.7
Not Affected
buildroot
master
3.6.3
Not Affected
openwrt
master
3.5.7-r1
Not Affected
openwrt
openwrt-25.12
3.5.7-r1
Not Affected
yocto
master
3.5.7
Not Affected
yocto
scarthgap
3.5.6
Not Affected

Resolved with patches#


openssl (yocto:kirkstone)

#
Title
Author
Resolve
1
rsa: add implicit rejection in PKCS#1 v1.5
Hubert Kario <hkario@redhat.com>
CVE-2023-50781
2
rsa: add test for the option to disable implicit rejection
Hubert Kario <hkario@redhat.com>
CVE-2023-50781
3
smime/pkcs7: disable the Bleichenbacher workaround
Hubert Kario <hkario@redhat.com>
CVE-2023-50781
4
rsa: add test vectors for the implicit rejection in RSA
Hubert Kario <hkario@redhat.com>
CVE-2023-50781
5
rsa: Add option to disable implicit rejection
Hubert Kario <hkario@redhat.com>
CVE-2023-50781
6
rsa: Skip the synthethic plaintext test with old FIPS
Hubert Kario <hkario@redhat.com>
CVE-2023-50781