First published: Wed Jan 13 2016(Updated: )
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/rsa | <3.3 | 3.3 |
Python Rsa Python | <3.3 | |
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 | |
openSUSE Leap | =42.1 | |
openSUSE openSUSE | =13.1 | |
openSUSE openSUSE | =13.2 |
https://bitbucket.org/sybren/python-rsa/pull-requests/14/security-fix-bb06-attack-in-verify-by/diff
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.