Lucene search

K
osvGoogleOSV:GHSA-537H-RV9Q-VVPH
HistoryMar 24, 2021 - 6:24 p.m.

Python-RSA decryption of ciphertext leads to DoS

2021-03-2418:24:39
Google
osv.dev
8

0.002 Low

EPSS

Percentile

64.8%

Python-RSA before 4.1 ignores leading ‘\0’ bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).

Rows per page:
1-10 of 231