A PKCS#1 v1.5 signature verification routine in all Android releases from CAF using the Linux kernel may not check padding.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2017-04-01 | patch vendor advisory |
http://www.securityfocus.com/bid/97329 | vdb entry third party advisory |
http://www.securitytracker.com/id/1038201 | vdb entry |