VulnerabilityModified
CVE-2023-5992
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant.
MEDIUM 5.9EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- opensc project/opensc · redhat/enterprise linux · redhat/enterprise linux eus · redhat/enterprise linux for arm 64 · redhat/enterprise linux for arm 64 eus · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux server aus · redhat/enterprise linux server for power little endian update services for sap solutions
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2024:0966Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0967Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-5992Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2248685Issue Tracking
- https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992Vendor Advisory
- https://www.usenix.org/system/files/usenixsecurity24-shagam.pdfExploit, Technical Description
- https://access.redhat.com/errata/RHSA-2024:0966Third Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0967Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-5992Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2248685Issue Tracking
- https://github.com/OpenSC/OpenSC/wiki/CVE-2023-5992Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/12/msg00026.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OWIZ5ZLO5ECYPLSTESCF7I7PQO5X6ZSU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJI2FWLY24EOPALQ43YPQEZMEP3APPPI/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UECKC7X4IM4YZQ5KRQMNBNKNOXLZC7RZ/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.