NIST’s CSRC has released a whitepaper detailing an attack against RSA digital signature verification using PKCS-1 padding.

NIST has designed a sequence of messages that can be used by a vendor to test the vulnerability of an implementation to this type of attack (see http://csrc.nist.gov/cryptval/anncmnts.htm). Concerned users should contact the vendor of their RSA digital signature application to request information on the vulnerability of their implementation.

Worth noting and checking into…