PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pycryptodome | Pycryptodome | * | 3.19.1 (excluding) |
Pycryptodomex | Pycryptodome | * | 3.19.1 (excluding) |
Red Hat Ansible Automation Platform 2.4 for RHEL 8 | RedHat | python3x-pycryptodomex-0:3.20.0-1.el8ap | * |
Red Hat Ansible Automation Platform 2.4 for RHEL 9 | RedHat | python-pycryptodomex-0:3.20.0-1.el9ap | * |
Red Hat Enterprise Linux 8 | RedHat | fence-agents-0:4.2.1-129.el8 | * |
Red Hat Enterprise Linux 8 | RedHat | resource-agents-0:4.9.0-54.el8 | * |
Red Hat Enterprise Linux 9 | RedHat | fence-agents-0:4.10.0-62.el9 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | fence-agents-0:4.10.0-20.el9_0.11 | * |
Red Hat Satellite 6.15 for RHEL 8 | RedHat | python-pycryptodomex-0:3.20.0-1.el8pc | * |
Red Hat Satellite 6.15 for RHEL 8 | RedHat | python-pycryptodomex-0:3.20.0-1.el8pc | * |
Pycryptodome | Ubuntu | bionic | * |
Pycryptodome | Ubuntu | esm-infra/bionic | * |
Pycryptodome | Ubuntu | focal | * |
Pycryptodome | Ubuntu | jammy | * |
Pycryptodome | Ubuntu | lunar | * |
Pycryptodome | Ubuntu | mantic | * |
Pycryptodome | Ubuntu | trusty | * |
Pycryptodome | Ubuntu | xenial | * |