OpenSSL FIPS Object Module PRNG Seed Vulnerability
BID:26652
Info
OpenSSL FIPS Object Module PRNG Seed Vulnerability
| Bugtraq ID: | 26652 |
| Class: | Design Error |
| CVE: |
CVE-2007-5502 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 29 2007 12:00AM |
| Updated: | Jan 04 2008 05:50PM |
| Credit: | Geoff Lowe discovered this issue. |
| Vulnerable: |
OpenSSL Project FIPS Object Module 1.1.1 |
| Not Vulnerable: | |
Discussion
OpenSSL FIPS Object Module PRNG Seed Vulnerability
OpenSSL is prone to a vulnerability that results in significantly weakened cryptographic security.
The OpenSSL FIPS Object Module PRNG implementation contains a serious flaw in the way the key and seed are determined. This results in a predictable PRNG output.
OpenSSL FIPS Object Module v1.1.1 is reported vulnerable.
NOTE: Changes to FIPS 140-2 validated software require official approval. The Open Source Software Institute (OSSI) has submitted patch information to the FIPS 140-2 test lab; the patches are pending approval. The estimated time to approval is currently unknown. The patches that were submitted and awaiting approval are available.
OpenSSL is prone to a vulnerability that results in significantly weakened cryptographic security.
The OpenSSL FIPS Object Module PRNG implementation contains a serious flaw in the way the key and seed are determined. This results in a predictable PRNG output.
OpenSSL FIPS Object Module v1.1.1 is reported vulnerable.
NOTE: Changes to FIPS 140-2 validated software require official approval. The Open Source Software Institute (OSSI) has submitted patch information to the FIPS 140-2 test lab; the patches are pending approval. The estimated time to approval is currently unknown. The patches that were submitted and awaiting approval are available.
Exploit / POC
OpenSSL FIPS Object Module PRNG Seed Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenSSL FIPS Object Module PRNG Seed Vulnerability
Solution:
Changes to FIPS 140-2 validated software require official approval. The Open Source Software Institute (OSSI) has submitted patch information to the FIPS 140-2 test lab; the patches are pending approval. The estimated time to approval is currently unknown. The patches that were submitted and awaiting approval are available.
The vendor has issued a fix that is to be considered a temporary mitigation until it receives official approval. Once validated, this fix will become an official patch.
Please see the referenced advisories for more information.
OpenSSL Project FIPS Object Module 1.1.1
Solution:
Changes to FIPS 140-2 validated software require official approval. The Open Source Software Institute (OSSI) has submitted patch information to the FIPS 140-2 test lab; the patches are pending approval. The estimated time to approval is currently unknown. The patches that were submitted and awaiting approval are available.
The vendor has issued a fix that is to be considered a temporary mitigation until it receives official approval. Once validated, this fix will become an official patch.
Please see the referenced advisories for more information.
OpenSSL Project FIPS Object Module 1.1.1
-
OpenSSL Project OpenSSL FIPS Module PRNG Patch (pending FIPS validation)
http://www.openssl.org/news/patch-CVE-2007-5502-2.txt
References
OpenSSL FIPS Object Module PRNG Seed Vulnerability
References:
References:
- OpenSSL Project (OpenSSL Project)
- OpenSSL Security Advisory [29-Nov-2007] (OpenSSL Project)
- VU#150249 - OpenSSL FIPS Object Module fails to properly generate random seeds (US-CERT)