CVE-2020-36316

MEDIUM

Relic < 2021-04-03 - Buffer Overflow

Title source: rule
STIX 2.1

Description

In RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can be present.

References (4)

Core 4
Core References
Product, Third Party Advisory x_refsource_misc
https://github.com/relic-toolkit/relic/
Exploit, Patch, Third Party Advisory x_refsource_misc
https://github.com/relic-toolkit/relic/issues/155

Scores

CVSS v3 5.5
EPSS 0.0026
EPSS Percentile 49.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-120
Status published
Products (1)
relic_project/relic < 2021-04-03
Published Apr 07, 2021
Tracked Since Feb 18, 2026