CVE-2023-50781

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:m2crypto_project:m2crypto:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:37

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2023-50781 - Third Party Advisory () https://access.redhat.com/security/cve/CVE-2023-50781 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2254426 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=2254426 - Issue Tracking

15 Feb 2024, 18:51

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2023-50781 - () https://access.redhat.com/security/cve/CVE-2023-50781 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2254426 - () https://bugzilla.redhat.com/show_bug.cgi?id=2254426 - Issue Tracking
Summary
  • (es) Se encontró una falla en m2crypto. Este problema puede permitir que un atacante remoto descifre mensajes capturados en servidores TLS que utilizan intercambios de claves RSA, lo que puede provocar la exposición de datos confidenciales o sensibles.
CVSS v2 : unknown
v3 : 5.9
v2 : unknown
v3 : 7.5
CWE CWE-203
CPE cpe:2.3:a:m2crypto_project:m2crypto:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
First Time Redhat
M2crypto Project m2crypto
Redhat enterprise Linux
M2crypto Project
Redhat update Infrastructure

05 Feb 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-05 21:15

Updated : 2024-11-21 08:37


NVD link : CVE-2023-50781

Mitre link : CVE-2023-50781

CVE.ORG link : CVE-2023-50781


JSON object : View

Products Affected

redhat

  • update_infrastructure
  • enterprise_linux

m2crypto_project

  • m2crypto
CWE
CWE-208

Observable Timing Discrepancy

CWE-203

Observable Discrepancy