{"id":"GHSA-87mp-xc4x-x8rh","aliases":[],"url":"https://o3.security/vulnerability/GHSA-87mp-xc4x-x8rh","summary":"asymmetricrypt/asymmetricrypt Padding Oracle Vulnerability in RSA Encryption","details":"The encryption and decryption process were vulnerable against the Bleichenbacher's attack, which is a padding oracle vulnerability disclosed in the 98'.\nThe issue was about the wrong padding utilized, which allowed to retrieve the encrypted content.\nThe OPENSSL_PKCS1_PADDING version, aka PKCS v1.5 was vulnerable (is the one set by default when using openssl_* methods), while the PKCS v2.0 isn't anymore (it's also called OAEP).\n\nA fix for this vulnerability was merged at https://github.com/Cosmicist/AsymmetriCrypt/pull/5/commits/a0318cfc5022f2a7715322dba3ff91d475ace7c6.","published":"2024-05-15T17:47:31Z","modified":"2024-11-29T05:32:28.469089Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"asymmetricrypt/asymmetricrypt","fixedVersion":null}],"fix":{"url":"https://github.com/Cosmicist/AsymmetriCrypt/pull/5","label":"Cosmicist/AsymmetriCrypt#5"},"references":[{"type":"WEB","url":"https://github.com/Cosmicist/AsymmetriCrypt/issues/4"},{"type":"WEB","url":"https://github.com/Cosmicist/AsymmetriCrypt/pull/5"},{"type":"PACKAGE","url":"https://github.com/Cosmicist/AsymmetriCrypt"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/asymmetricrypt/asymmetricrypt/2017-11-20.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:32:28.469089Z"}}