Lucene search

K
osvGoogleOSV:GHSA-8RJR-6QQ5-PJ9P
HistoryMay 14, 2022 - 12:59 a.m.

Python RSA allows attackers to spoof signatures

2022-05-1400:59:49
Google
osv.dev
11
python rsa
signature spoofing
crafted signature padding
berserk attack

AI Score

6.5

Confidence

Low

EPSS

0.004

Percentile

74.7%

The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.