Connect2id: Timing attack in Nimbus-Jose
MediumPublished Jun 21, 2023
### Summary Nimbus-Jose allows a chosen message attack that can decrypt RSA encrypted ciphertexts by measuring the decryption time. The attack uses the timing difference caused by an internal exception and allows to distinguish ciphertexts with valid PKCS #1 v1.5 paddings from ciphertexts with invalid paddings. ### Severity Moderate - This could allow the attacker to choose the messages that are encrypted and decrypted by a cryptographic system. This allows the attacker to learn more about the system and how it works, which can then be used to launch more sophisticated attacks. ### Proof of Concept https://github.com/google/wycheproof/commit/b063b4aedae951c69df014cd25fa6d69ae9e8cb9 ### Timeline **Date reported**: 3/03/2023 **Date fixed**: **Date disclosed**: 06/05/2023
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Nimbus-Jose Product | all versions | No fix yet |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Google advisories
All Google| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 242023 | AMD: Information Leak in Zen 2 | High7.1 | 2023-07-19 |
| Jun 292023 | Linux Kernel: eBPF verifier bug | Medium | ReferenceFurtherAnalysis |
| Jun 282023 | Harbor: Container Compromise Due to default Credentials | Critical | v1.3.18 |
| Jun 212023 | Portainer: Self-XSS | Low | 2.18.1 |
| Jun 152023 | Apple: Airpods Pro Device Link without Key | High | No fix yet |
| May 222023 | NPM: Ignore Script Bypass | Medium | Nopatchedversionsatthistime |