"value":"A timing-based side-channel flaw exists in the rust-openssl package, which could be sufficient to recover a plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages for decryption. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"Observable Discrepancy",
"cweId":"CWE-203"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"n/a",
"product":{
"product_data":[
{
"product_name":"upstream",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"affected"
}
}
]
}
}
]
}
},
{
"vendor_name":"Red Hat",
"product":{
"product_data":[
{
"product_name":"Red Hat Enterprise Linux 8",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
}
]
}
},
{
"product_name":"Red Hat Enterprise Linux 9",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
}
]
}
}
]
}
},
{
"vendor_name":"Fedora",
"product":{
"product_data":[
{
"product_name":"Fedora",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unknown"
}
}
]
}
},
{
"product_name":"Extra Packages for Enterprise Linux",