5.9

CVE-2023-5992

Exploit

Opensc: side-channel leaks while stripping encryption pkcs#1 padding

A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.16% 0.629
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
RedHat 5.6 2.2 3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

https://access.redhat.com/errata/RHSA-2024:0966
Third Party Advisory
https://access.redhat.com/errata/RHSA-2024:0967
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-5992
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2248685
Issue Tracking
https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992
Vendor Advisory
https://www.usenix.org/system/files/usenixsecurity24-shagam.pdf
Exploit
Technical Description
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OWIZ5ZLO5ECYPLSTESCF7I7PQO5X6ZSU/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJI2FWLY24EOPALQ43YPQEZMEP3APPPI/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UECKC7X4IM4YZQ5KRQMNBNKNOXLZC7RZ/
https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html