A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/20455 | vdb entry |
http://www.securiteam.com/unixfocus/5JP092AFPG.html | |
http://www.osvdb.org/16188 | vdb entry |
http://www.securityfocus.com/bid/13473 | vdb entry |
http://secunia.com/advisories/15233 | third party advisory |
http://www.securityfocus.org/archive/1/397649 | mailing list |