Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sjaeckel

#39858of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2017-8916
7.5
2016-11-06
Libtom · Libtomcrypt · CVE-2016-6129
**Name of the Vulnerable Software and Affected Versions** LibTomCrypt versions prior to 2.2.0 OP-TEE versions prior to 2.2.0 **Description** The issue arises from the rsa verify hash ex function in rsa verify hash.c, which fails to validate that the message length matches the ASN.1 encoded data length. This oversight enables remote attackers to forge RSA signatures or public certificates by exploiting a Bleichenbacher signature forgery attack. **Recommendations** For LibTomCrypt versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue. For OP-TEE versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the rsa verify hash ex function until a patch is available.