aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even if tag verification fails. If a program using the `aes-gcm` crate's `decrypt_in_place*` APIs accesses the buffer after decryption failure, it will contain a decryption of an unauthenticated input. Depending on the specific nature of the program this may enable Chosen Ciphertext Attacks (CCAs) which can cause a catastrophic breakage of the cipher including full plaintext recovery. Version 0.10.3 contains a fix for this issue.
                
            References
                    Configurations
                    History
                    21 Nov 2024, 08:23
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.7 | 
| References | () https://docs.rs/aes-gcm/latest/src/aes_gcm/lib.rs.html#309 - Product | |
| References | () https://github.com/RustCrypto/AEADs/security/advisories/GHSA-423w-p2w9-r7vq - Exploit, Vendor Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ROBB6TBDAGEQ2WIINR34F3DPSN3FND6K/ - Mailing List | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RYQCICN6BVC6I75O3F6W4VK4J3MOYDJU/ - Mailing List | |
| References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U67ZSMNX5V3WTBYPUYF45PSFG4SF5SGF/ - Mailing List | 
16 Feb 2024, 18:03
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-09-22 16:15
Updated : 2024-11-21 08:23
NVD link : CVE-2023-42811
Mitre link : CVE-2023-42811
CVE.ORG link : CVE-2023-42811
JSON object : View
Products Affected
                fedoraproject
- fedora
aes-gcm_project
- aes-gcm
CWE
                
                    
                        
                        CWE-347
                        
            Improper Verification of Cryptographic Signature
