nCipher PKCS#11 Symmetric Message Signature Verification Vulnerability
BID:5498
Info
nCipher PKCS#11 Symmetric Message Signature Verification Vulnerability
| Bugtraq ID: | 5498 |
| Class: | Design Error |
| CVE: |
CVE-2002-1446 |
| Remote: | No |
| Local: | No |
| Published: | Aug 19 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Published in an nCipher Security Advisory. |
| Vulnerable: |
nCipher nShield nCipher nForce |
| Not Vulnerable: |
nCipher nFast 800 nCipher nFast 75 nCipher nFast 300 nCipher nFast 150 |
Discussion
nCipher PKCS#11 Symmetric Message Signature Verification Vulnerability
nCipher produces a range of hardware and software security products which support a range of cryptographic operations. A vulnerability has been reported in the nCipher cryptographic library.
When messages signed with symmetric keys according to the RSA PKCS#11 specification are checked, invalid signatures may not be detected. The C_Verify function will return 'CKR_OK' regardless of the validity of the signature.
Applications which depend on this functionality may then fail to detect invalid signatures. Consequences of exploitation will be dependent on the product which uses the vulnerable library. It is likely that modification or injection of data in encrypted communications is possible.
This issue exists in versions 1.2.0 and later of the nCipher cryptographic library.
nCipher produces a range of hardware and software security products which support a range of cryptographic operations. A vulnerability has been reported in the nCipher cryptographic library.
When messages signed with symmetric keys according to the RSA PKCS#11 specification are checked, invalid signatures may not be detected. The C_Verify function will return 'CKR_OK' regardless of the validity of the signature.
Applications which depend on this functionality may then fail to detect invalid signatures. Consequences of exploitation will be dependent on the product which uses the vulnerable library. It is likely that modification or injection of data in encrypted communications is possible.
This issue exists in versions 1.2.0 and later of the nCipher cryptographic library.
Exploit / POC
nCipher PKCS#11 Symmetric Message Signature Verification Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
nCipher PKCS#11 Symmetric Message Signature Verification Vulnerability
Solution:
nCipher reports that updated versions of the library are available for Microsoft Windows, Linux, AIX, Solaris and HP-UX. Customers are advised to contact the vendor for updates, or to check the availability of fixes for other platforms.
Solution:
nCipher reports that updated versions of the library are available for Microsoft Windows, Linux, AIX, Solaris and HP-UX. Customers are advised to contact the vendor for updates, or to check the availability of fixes for other platforms.
References
nCipher PKCS#11 Symmetric Message Signature Verification Vulnerability
References:
References: