libtomcrypt: signature forgery
| Package(s): | libtomcrypt | CVE #(s): | CVE-2016-6129 | ||||||||
| Created: | September 7, 2016 | Updated: | November 7, 2016 | ||||||||
| Description: | From the Debian LTS advisory:
It was discovered that the implementation of RSA signature verification in libtomcrypt is vulnerable to the Bleichenbacher signature attack. If an RSA key with exponent 3 is used it may be possible to forge a PKCS#1 v1.5 signature signed by that key. | ||||||||||
| Alerts: |
| ||||||||||
