Security Advisory

CVE-2015-9258

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-31 21:00:00
Last updated 2024-08-06 08:43:41
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve data.