PT-2020-14094 · Jsrsasign · Jsrsasign

Published

2020-06-22

·

Updated

2023-01-28

·

CVE-2020-14967

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jsrsasign versions prior to 8.0.18
Description The issue concerns the RSA PKCS1 v1.5 decryption implementation in the jsrsasign package. It fails to detect ciphertext modification when '0' bytes are prepended to ciphertexts, allowing it to decrypt modified ciphertexts without error. This could potentially be exploited by an attacker to trigger memory corruption issues by prepending these bytes.
Recommendations For versions prior to 8.0.18, update to version 8.0.18 or later to resolve the issue.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2020-14967
GHSA-XXXQ-CHMP-67G4

Affected Products

Jsrsasign