Insecure digital certificates In libtomcrypt
Description
The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes it easier for remote attackers to forge RSA signatures or public certificates by leveraging a Bleichenbacher signature forgery attack.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 1.17-8 | ||
debian 12 | 1.17-8 | ||
debian 13 | 1.17-8 | ||
debian 14 | 1.17-8 |
Aliases
1. 2. 3. 4. 5.