Debian Security Advisory

DLA-612-1 libtomcrypt -- LTS security update

Date Reported:
06 Sep 2016
Affected Packages:
libtomcrypt
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-6129.
More information:

It was discovered that the implementation of RSA signature verification in libtomcrypt is vulnerable to the Bleichenbacher signature attack.

If an RSA key with exponent 3 is used it may be possible to forge a PKCS#1 v1.5 signature signed by that key.

For Debian 7 Wheezy, these problems have been fixed in version 1.17-3.2+deb7u1.

We recommend that you upgrade your libtomcrypt packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS