[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2017-864 ---- libtommath libtomcrypt

ID: oval:org.secpod.oval:def:1600741Date: (C)2017-08-04   (M)2021-09-11
Class: PATCHFamily: unix




possible OP-TEE Bleichenbacher attack:The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes it easier for remote attackers to forge RSA signatures or public certificates by leveraging a Bleichenbacher signature forgery attack

Platform:
Amazon Linux AMI
Product:
libtommath
libtomcrypt
Reference:
ALAS-2017-864
CVE-2016-6129
CVE    1
CVE-2016-6129
CPE    3
cpe:/o:amazon:linux
cpe:/a:libtommath:libtommath
cpe:/a:libtomcrypt:libtomcrypt

© SecPod Technologies