Lucene search

K
osvGoogleOSV:GHSA-CFM4-QJH2-4765
HistoryMar 18, 2022 - 11:09 p.m.

Improper Verification of Cryptographic Signature in node-forge

2022-03-1823:09:54
Google
osv.dev
150
crypto signature
node-forge
vulnerability patch
rsa pkcs#1 v1.5
implementation error

EPSS

0.001

Percentile

26.7%

Impact

RSA PKCS#1 v1.5 signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure that steals padding bytes and uses unchecked portion of the PKCS#1 encoded message to forge a signature when a low public exponent is being used.

Patches

The issue has been addressed in node-forge 1.3.0.

References

For more information, please see
“Bleichenbacher’s RSA signature forgery based on implementation error”
by Hal Finney.

For more information

If you have any questions or comments about this advisory: