CVE-2020-13757 affects Python-RSA versions before 4.1, where the library incorrectly ignores leading null bytes during ciphertext decryption. This vulnerability primarily impacts Canonical, Fedora, and Ubuntu Linux distributions utilizing Python-RSA. Rated with a CVSS score of 7.5 (High), this flaw presents a network-based attack vector with low complexity, potentially allowing attackers to infer the use of Python-RSA or trigger excessive memory allocation, though direct confidentiality or integrity impact is not specified. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1CPE matchmatch criteria | cpe:2.3:a:python-rsa_project:python-rsa:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.