Skip to main content

Vendor/product archive

libtom / libtomcrypt CVEs

Beta · best-effort

3 CVEs tagged to libtom / libtomcrypt1 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2019-17362

Published Oct 9, 2019

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-depe…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12437

Published Jun 15, 2018

LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attac…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6129

Published Feb 13, 2017

The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1