Junglewise Threat Intelligence

CVE-2016-1494: PYSEC-2016-10 - The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent

CVE-2016-1494 · Severity: low · CVSS 3 · Published 2016-01-13

Technologies: rsa (PyPI). Vendors: PyPI.

Executive brief

The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.

Affected products

  • PyPI rsa

Related threats