OpenSSL 'EVP_PKEY_verify_recover()' Invalid Return Value Security Bypass Vulnerability
BID:40503
Info
OpenSSL 'EVP_PKEY_verify_recover()' Invalid Return Value Security Bypass Vulnerability
| Bugtraq ID: | 40503 |
| Class: | Unknown |
| CVE: |
CVE-2010-1633 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2010 12:00AM |
| Updated: | Apr 13 2015 08:38PM |
| Credit: | Peter-Michael Hager |
| Vulnerable: |
VooDoo cIRCle XTelnet 0.4.5 VooDoo cIRCle 1.1.39 OpenSSL Project OpenSSL 1.0.2 OpenSSL Project OpenSSL 1.0 beta3 OpenSSL Project OpenSSL 1.0 Beta2 OpenSSL Project OpenSSL 1.0 beta1 OpenSSL Project OpenSSL 1.0 OpenSSL Project OpenSSL 1.0.0 Beta5 OpenSSL Project OpenSSL 1.0.0 Beta4 Kolab Kolab Groupware Server 2.2.3 Kolab Kolab Groupware Server 2.2.2 Kolab Kolab Groupware Server 2.2 Kolab Kolab Groupware Server 2.2-rc3 Kolab Kolab Groupware Server 2.2-rc1 Kolab Kolab Groupware Server 2.2 beta3 Kolab Kolab Groupware Server 2.2 beta1 Kolab Kolab Groupware Server 2.2 -rc2 |
| Not Vulnerable: |
VooDoo cIRCle XTelnet 0.4.6 VooDoo cIRCle 1.1.40 OpenSSL Project OpenSSL 1.0.0a Kolab Kolab Groupware Server 2.2.4 |
Discussion
OpenSSL 'EVP_PKEY_verify_recover()' Invalid Return Value Security Bypass Vulnerability
OpenSSL is prone to a security-bypass vulnerability.
Successful exploit may allow attackers to potentially bypass key checks in applications using the affected library; other attacks are also possible.
OpenSSL 1.0.0 is vulnerable; prior versions are not affected.
OpenSSL is prone to a security-bypass vulnerability.
Successful exploit may allow attackers to potentially bypass key checks in applications using the affected library; other attacks are also possible.
OpenSSL 1.0.0 is vulnerable; prior versions are not affected.
Exploit / POC
OpenSSL 'EVP_PKEY_verify_recover()' Invalid Return Value Security Bypass Vulnerability
The attacker will likely use standard tools to exploit this issue.
The attacker will likely use standard tools to exploit this issue.
Solution / Fix
OpenSSL 'EVP_PKEY_verify_recover()' Invalid Return Value Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Kolab Kolab Groupware Server 2.2-rc3
Kolab Kolab Groupware Server 2.2-rc1
Kolab Kolab Groupware Server 2.2 beta1
Kolab Kolab Groupware Server 2.2 -rc2
Kolab Kolab Groupware Server 2.2 beta3
OpenSSL Project OpenSSL 1.0 Beta2
OpenSSL Project OpenSSL 1.0
Kolab Kolab Groupware Server 2.2
Kolab Kolab Groupware Server 2.2.2
Kolab Kolab Groupware Server 2.2.3
Solution:
Updates are available. Please see the references for more information.
Kolab Kolab Groupware Server 2.2-rc3
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
Kolab Kolab Groupware Server 2.2-rc1
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
Kolab Kolab Groupware Server 2.2 beta1
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
Kolab Kolab Groupware Server 2.2 -rc2
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
Kolab Kolab Groupware Server 2.2 beta3
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
OpenSSL Project OpenSSL 1.0 Beta2
-
OpenSSL Project openssl-1.0.0a.tar.gz
http://www.openssl.org/source/openssl-1.0.0a.tar.gz
OpenSSL Project OpenSSL 1.0
-
OpenSSL Project openssl-1.0.0a.tar.gz
http://www.openssl.org/source/openssl-1.0.0a.tar.gz
Kolab Kolab Groupware Server 2.2
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
Kolab Kolab Groupware Server 2.2.2
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
Kolab Kolab Groupware Server 2.2.3
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
References
OpenSSL 'EVP_PKEY_verify_recover()' Invalid Return Value Security Bypass Vulnerability
References:
References:
- IBM Netcool System Service Monitor SSM 4.0 Fix Pack 1 README Netcool/System Serv (IBM)
- IBM Netcool System Service Monitor SSM 4.0 Fix Pack 14 README Netcool/System Ser (IBM)
- Kolab Server 2.2.4 Final Release (Kolab)
- OpenSSL Homepage (OpenSSL)
- Security Bulletin: IBM Tivoli Netcool System Service Monitors/Application Servic (IBM)
- Security Bulletin: IBM Tivoli Netcool System Service Monitors/Application Servic (IBM)
- An OpenSource VooDoo cIRCle - security advisory 20100624-02 (VooDoo cIRCle)
- HMC OpenSSL Upgrade to Address Cryptographic Vulnerabilities (IBM)
- IBM Tivoli Composite Application Manager for Transactions Internet Service Monit (IBM)
- OpenSSL Security Advisory [01-Jun-2010] (OpenSSL Project)
- Security Bulletin: IBM Endpoint Manager for Remote Control is affected by multip (IBM)
- Security Bulletin: IBM Sterling Connect:Enterprise for UNIX is affected by multi (IBM)
- Security Bulletin: IBM Sterling Connect:Express for UNIX is affected by multiple (IBM)
- Security Bulletin: IBM Tivoli Composite Application Monitoring for Transactions (IBM)
- Security Bulletin: OpenSSL vulnerability issues for IBM Cloudburst (IBM)
- Security Bulletin: OpenSSL vulnerability issues for IBM Service Delivery Manager (IBM)
- Security Bulletin: Tivoli Endpoint Manager for Remote Control is affected by mul (IBM)
- Security Bulletin: Tivoli Remote Control is affected by multiple OpenSSL vulnera (IBM)
- Storage HMC OpenSSL upgrade to address cryptographic vulnerabilities (IBM)