CVE-2015-9258: High severity docker vulnerability
Published Mar 31, 2018
·Updated
In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve data.
Affected Software
2 affected componentsFixes available
go/github.com/docker/notary<0.1.0
0.1.0
Docker Notary<0.1
Event History
Mar 31, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 14, 2022
Advisory Published
03:28 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-9258?
CVE-2015-9258 is considered a medium severity vulnerability due to potential signature forgery risks.
2
How do I fix CVE-2015-9258?
To fix CVE-2015-9258, update Docker Notary to version 0.1.0 or later.
3
What type of vulnerability is CVE-2015-9258?
CVE-2015-9258 is a Signature Algorithm Not Matched to Key vulnerability.
4
Who is affected by CVE-2015-9258?
CVE-2015-9258 affects all versions of Docker Notary prior to 0.1.0.
5
What can an attacker do with CVE-2015-9258?
An attacker exploiting CVE-2015-9258 could forge a signature by manipulating the signature algorithm field.