Lucene search

K
osvGoogleOSV:GHSA-X4JG-MJRX-434G
HistoryMar 18, 2022 - 11:10 p.m.

Improper Verification of Cryptographic Signature in node-forge

2022-03-1823:10:28
Google
osv.dev
39
cryptographic signature verification
node-forge
rsa pkcs#1 v1.5
implementation error
security patch
forge library
hal finney

EPSS

0.001

Percentile

36.5%

Impact

RSA PKCS#1 v1.5 signature verification code does not check for tailing garbage bytes after decoding a DigestInfo ASN.1 structure. This can allow padding bytes to be removed and garbage data added to forge a signature when a low public exponent is being used.

Patches

The issue has been addressed in node-forge 1.3.0.

References

For more information, please see
“Bleichenbacher’s RSA signature forgery based on implementation error”
by Hal Finney.

For more information

If you have any questions or comments about this advisory: