Logo
vulnerabilityCVE-2023-52323
Name
CVE-2023-52323
Source
NVD ( link)Debian ( link)
Description
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
Published Date
Updated Date
Workaround
-

Analysis#


Vulnerability Ratings#


5.9
CVSSv31
5.9
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
3.23.0
Not Affected
yocto
master
3.23.0
Not Affected
yocto
scarthgap
3.20.0
Not Affected
yocto
scarthgap
3.20.0
Not Affected

Resolved with patches#


python3-pycryptodome (yocto:kirkstone)

#
Title
Author
Resolve
1
Use constant-time (faster) padding decoding also for OAEP
Helder Eijs <helderijs@gmail.com>
CVE-2023-52323

python3-pycryptodomex (yocto:kirkstone)

#
Title
Author
Resolve
1
Use constant-time (faster) padding decoding also for OAEP
Narpat Mali <narpat.mali@windriver.com>
CVE-2023-52323