security advisorycriticaldebian It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3197-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler November 17, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : phpseclib Version : 1.0.19-3~deb10u1 CVE ID : CVE-2021-30130 It was discovered that phpseclib, a pure-PHP implementation of various cryptographic and arithmetic algorithms (v1), mishandles RSA PKCS#1 v1.5 signature verification. An attacker may get invalid signatures accepted, bypassing authorization control in specific situations. For Debian 10 buster, this problem has been fixed in version 1.0.19-3~deb10u1. We recommend that you upgrade your phpseclib packages. For the detailed security status of phpseclib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/phpseclib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3200-1 resolves vulnerabilities in openssl, improving encryption protocols for better data protection.. phpseclib security, Debian LTS advisory, cryptographic algorithms update. . Severity: Critical. LinuxSecurity.com Team
Nov 17, 2022 •Critical Debian LTS