{"uuid":"CPANSA-Crypt-OpenSSL-RSA-2024-2467","url":"https://access.redhat.com/security/cve/CVE-2024-2467","title":"A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send...","description":"A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.","origin":"CPANSA","severity":null,"published_at":"2024-04-25T00:00:00.000Z","withdrawn_at":null,"classification":null,"cvss_score":null,"cvss_vector":null,"references":["https://access.redhat.com/security/cve/CVE-2024-2467","https://bugzilla.redhat.com/show_bug.cgi?id=2269567","https://github.com/toddr/Crypt-OpenSSL-RSA/issues/42","https://people.redhat.com/~hkario/marvin/"],"source_kind":"cpansa","identifiers":["CPANSA-Crypt-OpenSSL-RSA-2024-2467","CVE-2024-2467"],"repository_url":"https://github.com/toddr/Crypt-OpenSSL-RSA","blast_radius":1.0,"created_at":"2026-05-22T09:42:16.610Z","updated_at":"2026-08-07T16:28:09.671Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/CPANSA-Crypt-OpenSSL-RSA-2024-2467","html_url":"https://advisories.ecosyste.ms/advisories/CPANSA-Crypt-OpenSSL-RSA-2024-2467","packages":[{"ecosystem":"cpan","package_name":"Crypt-OpenSSL-RSA","versions":[{"first_patched_version":"0.35","vulnerable_version_range":"\u003c 0.35"}],"purl":null,"statistics":{"dependent_packages_count":70,"dependent_repos_count":0,"downloads":null,"downloads_period":null},"affected_versions":[],"unaffected_versions":[]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/CPANSA-Crypt-OpenSSL-RSA-2024-2467/related_packages","related_advisories":[]}