Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.
Systems integrating libdigidocpp should update to
version 4.2.1 or later.
Users of DigiDoc applications should update to fixed
versions provided by the vendor:
DigiDoc4 - 4.8.2 or later, RIA DigiDoc Android
- 2.7.2 or later, and RIA DigiDoc iOS - 2.8.1 or later.
Signatures that were validated
with the vulnerable software versions should be revalidated.