Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200609-15] GnuTLS: RSA Signature Forgery Vulnerability Scan
Vulnerability Scan Summary
GnuTLS: RSA Signature Forgery
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200609-15
(GnuTLS: RSA Signature Forgery)
verify.c fails to properly handle excess data in
digestAlgorithm.parameters field while generating a hash when using an
RSA key with exponent 3. RSA keys that use exponent 3 are commonplace.
Remote attackers could forge PKCS #1 v1.5 signatures that are signed
with an RSA key, preventing GnuTLS from correctly verifying X.509 and
other certificates that use PKCS.
There is no known workaround at this time.
All GnuTLS users should update both packages:
# emerge --sync
# emerge --update --ask --verbose ">=net-libs/gnutls-1.4.4"
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.