Skip to main content

Vendor archive

libtom CVEs

Beta · best-effort

4 CVEs tagged to vendor libtom2 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-36328

Published Sep 1, 2023

Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denia…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17362

Published Oct 9, 2019

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-depe…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12437

Published Jun 15, 2018

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attac…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6129

Published Feb 13, 2017

The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1