aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even if tag verification fails. If a program using the `aes-gcm` crate's `decrypt_in_place*` APIs accesses the buffer after decryption failure, it will contain a decryption of an unauthenticated input. Depending on the specific nature of the program this may enable Chosen Ciphertext Attacks (CCAs) which can cause a catastrophic breakage of the cipher including full plaintext recovery. Version 0.10.3 contains a fix for this issue.
References
Configurations
History
21 Nov 2024, 08:23
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.7 |
References | () https://docs.rs/aes-gcm/latest/src/aes_gcm/lib.rs.html#309 - Product | |
References | () https://github.com/RustCrypto/AEADs/security/advisories/GHSA-423w-p2w9-r7vq - Exploit, Vendor Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ROBB6TBDAGEQ2WIINR34F3DPSN3FND6K/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RYQCICN6BVC6I75O3F6W4VK4J3MOYDJU/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U67ZSMNX5V3WTBYPUYF45PSFG4SF5SGF/ - Mailing List |
16 Feb 2024, 18:03
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-22 16:15
Updated : 2024-11-21 08:23
NVD link : CVE-2023-42811
Mitre link : CVE-2023-42811
CVE.ORG link : CVE-2023-42811
JSON object : View
Products Affected
fedoraproject
- fedora
aes-gcm_project
- aes-gcm
CWE
CWE-347
Improper Verification of Cryptographic Signature