Typical severity: High. Likelihood of attack: Low. An adversary exploits a cryptographic weakness in the signature verification algorithm implementation to generate a valid signature without knowing the key.
Use programs and products that contain cryptographic elements that have been thoroughly tested for flaws in the signature verification routines.