A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key.
https://exchange.xforce.ibmcloud.com/vulnerabilities/20455
http://www.securityfocus.org/archive/1/397649
http://www.securityfocus.com/bid/13473