CVE-2023-50781

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:m2crypto_project:m2crypto:-:*:*:*:*:*:*:*

History

15 Feb 2024, 18:51

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2023-50781 - () https://access.redhat.com/security/cve/CVE-2023-50781 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2254426 - () https://bugzilla.redhat.com/show_bug.cgi?id=2254426 - Issue Tracking
CWE CWE-203
Summary
  • (es) Se encontró una falla en m2crypto. Este problema puede permitir que un atacante remoto descifre mensajes capturados en servidores TLS que utilizan intercambios de claves RSA, lo que puede provocar la exposición de datos confidenciales o sensibles.
CVSS v2 : unknown
v3 : 5.9
v2 : unknown
v3 : 7.5
First Time Redhat enterprise Linux
M2crypto Project
Redhat
Redhat update Infrastructure
M2crypto Project m2crypto
CPE cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:m2crypto_project:m2crypto:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:update_infrastructure:4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

05 Feb 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-05 21:15

Updated : 2024-02-26 16:27


NVD link : CVE-2023-50781

Mitre link : CVE-2023-50781

CVE.ORG link : CVE-2023-50781


JSON object : View

Products Affected

m2crypto_project

  • m2crypto

redhat

  • enterprise_linux
  • update_infrastructure
CWE
CWE-203

Observable Discrepancy

CWE-208

Observable Timing Discrepancy