CVE-2016-6129Improper Input Validation in Libtomcrypt

Severity
7.5HIGHNVD
EPSS
0.1%
top 65.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13

Description

The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes it easier for remote attackers to forge RSA signatures or public certificates by leveraging a Bleichenbacher signature forgery attack.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/libtomcrypt< libtomcrypt 1.17-8 (bookworm)
Debianlibtomcrypt/libtomcrypt< 1.17-8+3
NVDop-tee/op-tee_os2.1.0

Patches

🔴Vulnerability Details

1
OSV
CVE-2016-6129: The rsa_verify_hash_ex function in rsa_verify_hash2017-02-13

📋Vendor Advisories

2
Red Hat
libtomcrypt: possible OP-TEE Bleichenbacher attack2016-08-26
Debian
CVE-2016-6129: libtomcrypt - The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in ...2016

💬Community

3
Bugzilla
CVE-2016-6129 libtomcrypt: possible OP-TEE Bleichenbacher attack2016-08-28
Bugzilla
CVE-2016-6129 libtomcrypt: possible OP-TEE Bleichenbacher attack [epel-all]2016-08-28
Bugzilla
CVE-2016-6129 libtomcrypt: possible OP-TEE Bleichenbacher attack [fedora-all]2016-08-28
CVE-2016-6129 — Improper Input Validation | cvebase