CVE-2023-52323
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
02 / AFFECTED SOFTWARE
Affected packages
60 explicit affected versions
53 explicit affected versions
53 explicit affected versions
46 explicit affected versions
46 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
05 / REFERENCES
Further evidence
- https://github.com/Legrandin/pycryptodome
- https://github.com/Legrandin/pycryptodome/blob/master/Changelog.rst
- https://github.com/Legrandin/pycryptodome/commit/0deea1bfe1489e8c80d2053bbb06a1aa0b181ebd
- https://github.com/advisories/GHSA-j225-cvw7-qrx7
- https://github.com/pypa/advisory-database/tree/main/vulns/pycryptodomex/PYSEC-2024-3.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2023-52323
- https://pypi.org/project/pycryptodome
- https://pypi.org/project/pycryptodomex/#history
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52323.json