VDB
Sign up
—

PYSEC-2020-99

Quick fix

PYSEC-2020-99 — rsa: upgrade to the fixed version with the command below.

pip install --upgrade 'rsa>=4.1'

Details

Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/rsa
Introduced in: 0Fixed in: 4.1
Fixpip install --upgrade 'rsa>=4.1'

References