{"id":"GHSA-87mp-xc4x-x8rh","summary":"asymmetricrypt/asymmetricrypt Padding Oracle Vulnerability in RSA Encryption","details":"The encryption and decryption process were vulnerable against the Bleichenbacher's attack, which is a padding oracle vulnerability disclosed in the 98'.\nThe issue was about the wrong padding utilized, which allowed to retrieve the encrypted content.\nThe OPENSSL_PKCS1_PADDING version, aka PKCS v1.5 was vulnerable (is the one set by default when using openssl_* methods), while the PKCS v2.0 isn't anymore (it's also called OAEP).\n\nA fix for this vulnerability was merged at https://github.com/Cosmicist/AsymmetriCrypt/pull/5/commits/a0318cfc5022f2a7715322dba3ff91d475ace7c6.","modified":"2024-11-29T05:32:28.469089Z","published":"2024-05-15T17:47:31Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-327"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-15T17:47:31Z"},"references":[{"type":"WEB","url":"https://github.com/Cosmicist/AsymmetriCrypt/issues/4"},{"type":"WEB","url":"https://github.com/Cosmicist/AsymmetriCrypt/pull/5"},{"type":"PACKAGE","url":"https://github.com/Cosmicist/AsymmetriCrypt"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/asymmetricrypt/asymmetricrypt/2017-11-20.yaml"}],"affected":[{"package":{"name":"asymmetricrypt/asymmetricrypt","ecosystem":"Packagist","purl":"pkg:composer/asymmetricrypt/asymmetricrypt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.3.0"}]}],"versions":["0.1.0","0.2.0","0.2.1","0.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-87mp-xc4x-x8rh/GHSA-87mp-xc4x-x8rh.json"}}],"schema_version":"1.9.0"}