Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1494

Опубликовано: 13 янв. 2016
Источник: debian

Описание

The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-rsafixed3.2.3-1.1package
python-rsafixed3.1.4-1+deb8u1jessiepackage

Примечания

  • proposed fix: https://bitbucket.org/sybren/python-rsa/pull-requests/14/security-fix-bb06-attack-in-verify-by/diff

  • https://blog.filippo.io/bleichenbacher-06-signature-forgery-in-python-rsa/

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 10 лет назад

The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.

CVSS3: 5.3
nvd
около 10 лет назад

The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.

msrc
5 месяцев назад

The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.

suse-cvrf
около 10 лет назад

Security update for python-rsa

suse-cvrf
около 10 лет назад

Security update for python-rsa