CVE Vulnerabilities

CVE-2021-30130

Improper Verification of Cryptographic Signature

Published: Apr 06, 2021 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

NameVendorStart VersionEnd Version
PhpseclibPhpseclib*2.0.31 (excluding)
PhpseclibPhpseclib3.0 (including)3.0.7 (excluding)
Php-phpseclibUbuntubionic*
Php-phpseclibUbuntuesm-apps/focal*
Php-phpseclibUbuntufocal*
Php-phpseclibUbuntukinetic*
Php-phpseclibUbuntulunar*
Php-phpseclibUbuntumantic*
Php-phpseclibUbuntutrusty*
Php-phpseclibUbuntuupstream*
Php-phpseclibUbuntuxenial*
Php-phpseclib3Ubuntukinetic*
Php-phpseclib3Ubuntulunar*
Php-phpseclib3Ubuntumantic*
Php-phpseclib3Ubuntutrusty*
Php-phpseclib3Ubuntuupstream*
Php-phpseclib3Ubuntuxenial*
PhpseclibUbuntubionic*
PhpseclibUbuntuesm-apps/focal*
PhpseclibUbuntufocal*
PhpseclibUbuntugroovy*
PhpseclibUbuntuhirsute*
PhpseclibUbuntuimpish*
PhpseclibUbuntukinetic*
PhpseclibUbuntulunar*
PhpseclibUbuntumantic*
PhpseclibUbuntutrusty*
PhpseclibUbuntuxenial*

References