7.5
CVSSv3

CVE-2023-50781

Published: 05/02/2024 Updated: 26/02/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw was found in m2crypto. This issue may allow a remote malicious user to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux 8.0

redhat enterprise linux 9.0

redhat update infrastructure 4

m2crypto project m2crypto -

Vendor Advisories

Debian Bug report logs - #1059292 m2crypto: CVE-2023-50781 Package: src:m2crypto; Maintainer for src:m2crypto is Sandro Tosi <morph@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 22 Dec 2023 12:39:02 UTC Severity: important Tags: security, upstream Found in version m2crypto/0380-41 Fo ...
Description<!---->A flaw was found in m2crypto This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive dataA flaw was found in m2crypto This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key ...