CVE-2016-1494
Python RSA allows attackers to spoof signatures
5.3
MEDIUM
CVSS 3.1
EPSS 7.1%
Description
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
How to fix CVE-2016-1494
To remediate CVE-2016-1494, upgrade the affected package to a fixed version below.
- Debian/python-rsa—upgrade to 3.2.3-1.1 or later
- —upgrade to 3.3 or later
- —upgrade to 3.3 or later
Is CVE-2016-1494 being exploited?
Moderate — EPSS is 7.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 3.2.3-1.1
- from 0, < 3.3
- from 0, < 3.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |