A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux | Redhat | 8.0 (including) | 8.0 (including) |
Enterprise_linux | Redhat | 9.0 (including) | 9.0 (including) |
M2crypto | Ubuntu | bionic | * |
M2crypto | Ubuntu | lunar | * |
M2crypto | Ubuntu | mantic | * |
M2crypto | Ubuntu | trusty | * |
M2crypto | Ubuntu | trusty/esm | * |
M2crypto | Ubuntu | xenial | * |