MGASA-2020-0364

Source
https://advisories.mageia.org/MGASA-2020-0364.html
Import Source
https://advisories.mageia.org/MGASA-2020-0364.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0364
Related
Published
2020-09-06T20:33:09Z
Modified
2020-09-06T19:53:35Z
Summary
Updated python-rsa packages fix security vulnerability
Details

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation). (CVE-2020-13757)

References
Credits

Affected packages

Mageia:7 / python-rsa

Package

Name
python-rsa
Purl
pkg:rpm/mageia/python-rsa?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0-1.1.mga7

Ecosystem specific

{
    "section": "core"
}