GHSA-j225-cvw7-qrx7

Suggest an improvement
Source
https://github.com/advisories/GHSA-j225-cvw7-qrx7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-j225-cvw7-qrx7/GHSA-j225-cvw7-qrx7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j225-cvw7-qrx7
Aliases
Related
Published
2024-01-05T06:30:19Z
Modified
2024-10-21T21:02:02.395709Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption
Details

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

References

Affected packages

PyPI / pycryptodomex

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.19.1

Affected versions

3.*

3.4.1
3.4.2
3.4.3
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.4.11
3.4.12
3.5.1
3.6.0
3.6.1
3.6.3
3.6.4
3.6.5
3.6.6
3.7.0
3.7.1
3.7.2
3.7.3
3.8.0
3.8.1
3.8.2
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.6
3.9.7
3.9.8
3.9.9
3.10.1
3.10.3
3.10.4
3.11.0
3.12.0
3.13.0
3.14.0
3.14.1
3.15.0
3.16.0
3.17
3.18.0
3.19.0

PyPI / pycryptodome

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.19.1

Affected versions

3.*

3.0rc1
3.0
3.1
3.2
3.2.1
3.3
3.3.1
3.4
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.4.9
3.4.11
3.5.0
3.5.1
3.6.0
3.6.1
3.6.3
3.6.4
3.6.5
3.6.6
3.7.0
3.7.1
3.7.2
3.7.3
3.8.0
3.8.1
3.8.2
3.9.0
3.9.1
3.9.2
3.9.3
3.9.4
3.9.6
3.9.7
3.9.8
3.9.9
3.10.1
3.10.3
3.10.4
3.11.0
3.12.0
3.13.0
3.14.0
3.14.1
3.15.0
3.16.0
3.17
3.18.0
3.19.0