Description
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-0032 | The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack. |
Github GHSA |
GHSA-8rjr-6qq5-pj9p | Python RSA allows attackers to spoof signatures |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T22:55:14.815Z
Reserved: 2016-01-04T00:00:00.000Z
Link: CVE-2016-1494
No data.
Status : Modified
Published: 2016-01-13T15:59:02.787
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-1494
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA