@techreport{vangeest-lamps-cms-euf-cma-signeddata-01, number = {draft-vangeest-lamps-cms-euf-cma-signeddata-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-vangeest-lamps-cms-euf-cma-signeddata/01/}, author = {Daniel Van Geest and Falko Strenzke}, title = {{EUF-CMA for the Cryptographic Message Syntax (CMS) SignedData}}, pagetotal = 15, year = 2025, month = mar, day = 18, abstract = {The Cryptographic Message Syntax (CMS) has different signature verification behaviour based on whether signed attributes are present or not. This results in a potential existential forgery vulnerability in CMS and protocols which use CMS. This document describes the vulnerability and lists a number of potential mitigations for LAMPS working group discussion.}, }