The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-rsa | Jul 30, 2024 | Jan 13, 2016 |
| Freebsd | — | Upgrade py35-rsaUpgrade py27-rsaUpgrade py34-rsaUpgrade py33-rsaUpgrade py32-rsa | Dec 10, 2025 | Feb 4, 2016 |
| Suse | — | Upgrade python-rsa | Feb 2, 2016 | Jan 13, 2016 |
| Ubuntu | — | Upgrade python-rsa | Nov 19, 2024 | Jan 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub