Claymore PureTLS Injection Attack Vulnerability
BID:4237
Info
Claymore PureTLS Injection Attack Vulnerability
| Bugtraq ID: | 4237 |
| Class: | Unknown |
| CVE: |
CVE-2002-0420 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Published in a PureTLS Security Announcement. |
| Vulnerable: |
Claymore Systems Inc PureTLS 0.9 b1 |
| Not Vulnerable: |
Claymore Systems Inc PureTLS 0.9 b2 |
Discussion
Claymore PureTLS Injection Attack Vulnerability
Claymore PureTLS is a Java implementation of the SSLv3 and TLS protocols. The Secure Socket Layer (SSL) protocol is used to provide private communications over the internet. The Transit Layer Security (TLS) protocol is intended to provide privacy and data integrity, and encapsulate higher level protocols.
A vulnerability has been announced in some versions of PureTLS. Reportedly, earlier versions of PureTLS suffer from a possible injection attack. Although technical details are not currently available, this class of attack may allow malicious parties to subvert protected communications.
Claymore PureTLS is a Java implementation of the SSLv3 and TLS protocols. The Secure Socket Layer (SSL) protocol is used to provide private communications over the internet. The Transit Layer Security (TLS) protocol is intended to provide privacy and data integrity, and encapsulate higher level protocols.
A vulnerability has been announced in some versions of PureTLS. Reportedly, earlier versions of PureTLS suffer from a possible injection attack. Although technical details are not currently available, this class of attack may allow malicious parties to subvert protected communications.
Exploit / POC
Claymore PureTLS Injection Attack Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Claymore PureTLS Injection Attack Vulnerability
Solution:
An updated version is available:
Claymore Systems Inc PureTLS 0.9 b1
Solution:
An updated version is available:
Claymore Systems Inc PureTLS 0.9 b1
-
Claymore Systems, Inc puretls-0.9b2.tar.gz
http://www.rtfm.com/cgi-bin/distrib.cgi?puretls-0.9b2.tar.gz
References
Claymore PureTLS Injection Attack Vulnerability
References:
References:
- PureTLS Homepage (Claymore Systems, Inc)