Jump to content

Advisories MDKSA-2006:166: Updated gnutls packages fixes PKCS signature verification issue.


paul
 Share

Recommended Posts

verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3,

does not properly handle excess data in the digestAlgorithm.parameters

field when generating a hash, which allows remote attackers to forge a

PKCS #1 v1.5 signature that is signed by that RSA key and prevents

GnuTLS from correctly verifying X.509 and other certificates that use

PKCS, a variant of CVE-2006-4339.

 

The provided packages have been patched to correct this issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...