Cryptographic issues in perl-crypt-openssl-rsa - CVE-2024-2467

 

Cryptographic issues in perl-crypt-openssl-rsa - CVE-2024-2467

Published: June 25, 2025


Vulnerability identifier: #VU111947
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2467
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to decrypt sensitive information.

A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.


Affected software

perl-crypt-openssl-rsa
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Fedora
Basesystem Module
openSUSE Leap
openEuler
perl-Crypt-OpenSSL-RSA-debuginfo
perl-Crypt-OpenSSL-RSA-debugsource
perl-Crypt-OpenSSL-RSA
perl-Crypt-OpenSSL-RSA-help

How to mitigate CVE-2024-2467

Install updates from vendor's website.

perl-Crypt-OpenSSL-RSA-debuginfo - addressed in versions 0.28-10.3.1, 0.28-150600.19.3.1
perl-Crypt-OpenSSL-RSA-debugsource - addressed in versions 0.28-10.3.1, 0.28-150600.19.3.1
perl-Crypt-OpenSSL-RSA - addressed in versions 0.28-10.3.1, 0.28-150600.19.3.1
perl-Crypt-OpenSSL-RSA-debuginfo - update to 0.35-1
perl-Crypt-OpenSSL-RSA - update to 0.35-1
perl-Crypt-OpenSSL-RSA-help - update to 0.35-1
perl-Crypt-OpenSSL-RSA-debugsource - update to 0.35-1
perl-Crypt-OpenSSL-RSA - addressed in versions 0.35-1.el10_0, 0.35-1.el10_1, 0.35-1.fc41, 0.35-1.fc42, 0.35-1.fc43

External References

Related Security Bulletins