CVE-2018-16253

CVSS v3.0 5.9 (Medium)
59% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.18 % (55th)
0.18% Progress
Affected Products 1

In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not properly verify the ASN.1 metadata. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation through fake X.509 certificates. This is an even more permissive variant of CVE-2006-4790 and CVE-2014-1568.

Weaknesses
CWE-347
Improper Verification of Cryptographic Signature
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2018-11-07 20:29:00
(5 years ago)
Updated Date
2018-12-13 18:06:42
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Axtls Project Axtls 2.1.3 and prior versions cpe:2.3:a:axtls_project:axtls <= 2.1.3
Loading...
Loading...
Loading...
Loading...
Loading...