Debian Security Advisory
DLA-612-1 libtomcrypt -- LTS security update
- Date Reported:
- 06 Sep 2016
- Affected Packages:
- libtomcrypt
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2016-6129.
- More information:
-
It was discovered that the implementation of RSA signature verification in libtomcrypt is vulnerable to the Bleichenbacher signature attack.
If an RSA key with exponent 3 is used it may be possible to forge a PKCS#1 v1.5 signature signed by that key.
For Debian 7
Wheezy
, these problems have been fixed in version 1.17-3.2+deb7u1.We recommend that you upgrade your libtomcrypt packages.
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS