A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS (by setting the USE_RSA_SUITES define), it will be vulnerable to the timing variant of the Bleichenbacher attack. An attacker that is able to perform a large number of connections to the server will be able to decrypt RSA ciphertexts or forge signatures using server's certificate.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-16001 A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the support for RSA key exchange ciphersuites in TLS (by setting the USE_RSA_SUITES define), it will be vulnerable to the timing variant of the Bleichenbacher attack. An attacker that is able to perform a large number of connections to the server will be able to decrypt RSA ciphertexts or forge signatures using server's certificate.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2024-08-01T17:41:16.108Z

Reserved: 2024-01-02T20:49:45.368Z

Link: CVE-2024-0202

cve-icon Vulnrichment

Updated: 2024-08-01T17:41:16.108Z

cve-icon NVD

Status : Modified

Published: 2024-02-05T21:15:11.450

Modified: 2024-11-21T08:46:03.343

Link: CVE-2024-0202

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.