
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-36316 affects RELIC versions before 2021-04-03, where a buffer overflow vulnerability exists in PKCS#1 v1.5 signature verification due to the presence of garbage bytes (NVD, CVE).
The vulnerability stems from issues in the PKCS#1 v1.5 signature verification code where pad_len can be set to a very small number when given a malformed signature with very short padding. The code doesn't enforce requirements that the padding must be at least 8 bytes long and long enough to prevent extra trailing bytes after the hash value. This can lead to buffer overflow conditions when calculating buffer sizes (GitHub Issue).
The vulnerability could allow attackers to cause buffer overflow conditions, potentially leading to arbitrary code execution or system crashes. The issue is particularly concerning as it affects the signature verification process, a critical security component (NVD).
A proof-of-concept exploit has been demonstrated that can trigger a Segmentation Fault during signature verification. The vulnerability can be exploited by crafting malicious signatures with specifically formatted padding (GitHub Issue).
The vulnerability was fixed in RELIC version 2021-04-03 by inverting the padding check logic and implementing more rigorous validation. Users should upgrade to this version or later to address the vulnerability (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."