Candidate: CVE-2016-6129 PublicDate: 2017-02-13 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6129 https://github.com/OP-TEE/optee_os/commit/30d13250c390c4f56adefdcd3b64b7cc672f9fe2 https://github.com/libtom/libtomcrypt/commit/5eb9743410ce4657e9d54fef26a2ee31a1b5dd09 Description: The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes it easier for remote attackers to forge RSA signatures or public certificates by leveraging a Bleichenbacher signature forgery attack. Ubuntu-Description: It was discovered that LibTomCrypt incorrectly handled RSA signatures or public certificates. An attacker could possibly use this issue to make a Bleichenbacher signature forgery attack. Notes: tyhicks> Per Debian's security tracker, the underlying issue looks to be in libtomcrypt Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_libtomcrypt: upstream_libtomcrypt: needs-triage precise_libtomcrypt: released (1.17-3.2+deb7u1ubuntu0.1) precise/esm_libtomcrypt: DNE (precise was released [1.17-3.2+deb7u1ubuntu0.1]) trusty_libtomcrypt: released (1.17-5ubuntu0.1) trusty/esm_libtomcrypt: released (1.17-5ubuntu0.1) vivid/stable-phone-overlay_libtomcrypt: DNE vivid/ubuntu-core_libtomcrypt: DNE xenial_libtomcrypt: released (1.17-7ubuntu0.1) yakkety_libtomcrypt: ignored (reached end-of-life) zesty_libtomcrypt: ignored (reached end-of-life) artful_libtomcrypt: ignored (reached end-of-life) bionic_libtomcrypt: not-affected (1.17-8) devel_libtomcrypt: not-affected (1.17-8)