High severityNVD Advisory· Published Jun 1, 2020· Updated Aug 4, 2024
CVE-2020-13757
CVE-2020-13757
Description
Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rsaPyPI | < 4.1 | 4.1 |
Affected products
26- Python-RSA/Python-RSAdescription
- ghsa-coords25 versionspkg:pypi/rsapkg:rpm/opensuse/python-rsa&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python-rsa&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-rsa&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-rsa&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-rsa&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012pkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/python-rsa&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/python-rsa&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/python-rsa&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/python-rsa&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/python-rsa&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/python-rsa&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-rsa&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-rsa&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python-rsa&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 4.1+ 24 more
- (no CPE)range: < 4.1
- (no CPE)range: < 3.4.2-lp152.4.3.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 4.7.2-1.5
- (no CPE)range: < 3.4.2-3.3.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.1.4-12.16.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.4.2-3.4.1
- (no CPE)range: < 3.1.4-12.16.1
- (no CPE)range: < 3.4.2-3.3.1
- (no CPE)range: < 3.4.2-4.4.1
- (no CPE)range: < 3.4.2-3.3.1
- (no CPE)range: < 3.4.2-4.4.1
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-537h-rv9q-vvphghsaADVISORY
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2KILTHBHNSDUCYV22ODLOKTICJJ7JQIQ/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZYB65VNILRBTXL6EITQTH2PZPK7I23MW/mitrevendor-advisoryx_refsource_FEDORA
- nvd.nist.gov/vuln/detail/CVE-2020-13757ghsaADVISORY
- usn.ubuntu.com/4478-1/mitrevendor-advisoryx_refsource_UBUNTU
- github.com/pypa/advisory-database/tree/main/vulns/rsa/PYSEC-2020-99.yamlghsaWEB
- github.com/sybrenstuvel/python-rsa/issues/146ghsax_refsource_MISCWEB
- github.com/sybrenstuvel/python-rsa/issues/146ghsax_refsource_CONFIRMWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2KILTHBHNSDUCYV22ODLOKTICJJ7JQIQghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZYB65VNILRBTXL6EITQTH2PZPK7I23MWghsaWEB
- usn.ubuntu.com/4478-1ghsaWEB
News mentions
0No linked articles in our index yet.