A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.
References
Configurations
History
No history.
Information
Published : 2024-01-31 05:15
Updated : 2024-04-25 17:15
NVD link : CVE-2024-0914
Mitre link : CVE-2024-0914
CVE.ORG link : CVE-2024-0914
JSON object : View
Products Affected
redhat
- enterprise_linux
opencryptoki_project
- opencryptoki
CWE
CWE-203
Observable Discrepancy