A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in macOS Sonoma 14.3, watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apple

Published: 2024-01-23T00:25:38.999Z

Updated: 2024-01-23T00:25:38.999Z

Reserved: 2024-01-12T22:22:21.477Z


Link: CVE-2024-23218

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2024-01-23T01:15:11.403

Modified: 2024-03-13T23:15:46.027


Link: CVE-2024-23218

JSON object: View

cve-icon Redhat Information

No data.

CWE