CVE-2020-25657 PUBLISHED

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat from this vulnerability is to confidentiality.

EPSS 0.41% · 60.9th percentile

Risk Scores

EPSS Score
0.41%
60.9th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10m2crypto0.42.0-2.1build1, 0, 0.42.0-3
Ubuntu:22.04:LTSm2crypto0, 0.38.0-1ubuntu3, 0.38.0-1ubuntu5
Ubuntu:14.04:LTSm2crypto0, 0.21.1-3ubuntu3, 0.21.1-3ubuntu4
Ubuntu:16.04:LTSm2crypto0, 0.21.1-3ubuntu5, 0.22.6~rc4-1ubuntu1
Ubuntu:20.04:LTSm2crypto0.31.0-9ubuntu1, 0, 0.31.0-6build1
Ubuntu:18.04:LTSm2crypto0, 0.27.0-4build1, 0.27.0-4
Ubuntu:24.04:LTSm2crypto0.40.1-0ubuntu1, 0.40.1-1, 0.40.1-2build1

Timeline

References

Open in Interactive Console →