RSA Keon Certificate Authority Log File Verification Bypass Vulnerabilities
BID:20136
CVE-2006-4991 |Info
RSA Keon Certificate Authority Log File Verification Bypass Vulnerabilities
| Bugtraq ID: | 20136 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 21 2006 12:00AM |
| Updated: | Sep 21 2006 10:41PM |
| Credit: | Arhont Ltd. discovered these vulnerabilities. |
| Vulnerable: |
Rsa Keon Certificate Authority 6.5.1 Rsa Keon Certificate Authority 6.6 |
| Not Vulnerable: | |
Discussion
RSA Keon Certificate Authority Log File Verification Bypass Vulnerabilities
RSA Keon is susceptible to two logfile-verification-bypass vulnerabilities. These issues are due to design flaws in the implementation of the digital signature process for logfiles. The use of cryptographic hashes to sign log entries may add an increased level of trust for users relying on the logs for auditing purposes.
These issues allow local attackers to remove and modify logfile contents, aiding them in hiding malicious activity from certificate-authority auditors.
RSA Keon versions 6.5.1 and 6.6 are vulnerable to these issues; other versions may also be affected.
RSA Keon is susceptible to two logfile-verification-bypass vulnerabilities. These issues are due to design flaws in the implementation of the digital signature process for logfiles. The use of cryptographic hashes to sign log entries may add an increased level of trust for users relying on the logs for auditing purposes.
These issues allow local attackers to remove and modify logfile contents, aiding them in hiding malicious activity from certificate-authority auditors.
RSA Keon versions 6.5.1 and 6.6 are vulnerable to these issues; other versions may also be affected.
Exploit / POC
RSA Keon Certificate Authority Log File Verification Bypass Vulnerabilities
Attackers use standard file-editing utilities to exploit these issues.
Attackers use standard file-editing utilities to exploit these issues.
Solution / Fix
RSA Keon Certificate Authority Log File Verification Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
RSA Keon Certificate Authority Log File Verification Bypass Vulnerabilities
References:
References:
- RSA Homepage (RSA Security)
- RSA Keyon Log verification bypass vulnerability (Andrei Mikhailovsky
)