Skip to content
GoogleGHSA-vpx7-57c6-vgvq

Connect2id: Timing attack in Nimbus-Jose

MediumPublished Jun 21, 2023

### Summary Nimbus-Jose allows a chosen message attack that can decrypt RSA encrypted ciphertexts by measuring the decryption time. The attack uses the timing difference caused by an internal exception and allows to distinguish ciphertexts with valid PKCS #1 v1.5 paddings from ciphertexts with invalid paddings. ### Severity Moderate - This could allow the attacker to choose the messages that are encrypted and decrypted by a cryptographic system. This allows the attacker to learn more about the system and how it works, which can then be used to launch more sophisticated attacks. ### Proof of Concept https://github.com/google/wycheproof/commit/b063b4aedae951c69df014cd25fa6d69ae9e8cb9 ### Timeline **Date reported**: 3/03/2023 **Date fixed**: **Date disclosed**: 06/05/2023

GitHub advisory

Affected versions

PackageAffectedFixed in
Nimbus-Jose
Product
all versionsNo fix yet
Details and references

More Google advisories

All Google
Advisory
AMD: Information Leak in Zen 2
High7.1Jul 24, 2023
Linux Kernel: eBPF verifier bug
MediumJun 29, 2023
Harbor: Container Compromise Due to default Credentials
CriticalJun 28, 2023
Portainer: Self-XSS
LowJun 21, 2023
Apple: Airpods Pro Device Link without Key
HighJun 15, 2023
NPM: Ignore Script Bypass
MediumMay 22, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.