Lucene search

K
osvGoogleOSV:CVE-2018-15836
HistorySep 26, 2018 - 9:29 p.m.

CVE-2018-15836

2018-09-2621:29:00
Google
osv.dev
2

6.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.0%

In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used. IKEv2 signature verification is affected when RAW RSA keys are used.

6.9 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.0%

Related for OSV:CVE-2018-15836