#VU111947 Cryptographic issues in perl-crypt-openssl-rsa - CVE-2024-2467

 

#VU111947 Cryptographic issues in perl-crypt-openssl-rsa - CVE-2024-2467

Published: June 25, 2025


Vulnerability identifier: #VU111947
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-2467
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
perl-crypt-openssl-rsa
Software vendor:
CPAN

Description

The vulnerability allows an attacker to decrypt sensitive information.

A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.


Remediation

Install updates from vendor's website.

External links