Multiple Vendor PKCS#1 Vulnerability
BID:676
Info
Multiple Vendor PKCS#1 Vulnerability
| Bugtraq ID: | 676 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 26 1998 12:00AM |
| Updated: | Jun 26 1998 12:00AM |
| Credit: | The vulnerability was discovered by Daniel Bleichenbacher <[email protected]> of Bell Labs. |
| Vulnerable: |
SSLeay SSLeay 0.9 SSLeay SSLeay 0.8.1 SSLeay SSLeay 0.6.6 Open Market Secure WebServer 2.1 Netscape Proxy Server 3.5.1 Netscape Proxy Server 3.5 SP1 Netscape Proxy Server 2.5 SP4 Netscape Messaging Server 3.54 Netscape FastTrack Server 3.0.1 B Netscape FastTrack Server 2.0.1 C Netscape Enterprise Server 3.51 Netscape Enterprise Server 3.0.1 B Netscape Enterprise Server 3.0 L Netscape Enterprise Server 2.0.1 C Netscape Directory Server 3.12 Netscape Directory Server 3.1 P1 Netscape Directory Server 1.3 P5 Netscape Collabra Server 3.5.2 Netscape Certificate Server 1.0 P1 Microsoft Site Server Commerce Edition 3.0 i386 Microsoft Site Server Commerce Edition 3.0 alpha Microsoft Site Server 3.0 i386 Microsoft IIS 4.0 Microsoft IIS 3.0 Microsoft Exchange Server 5.5 Microsoft Exchange Server 5.0 C2Net StrongHold Web Server 2.3 C2Net StrongHold Web Server 2.2 C2Net StrongHold Web Server 2.0.1 |
| Not Vulnerable: |
Netscape Messaging Server 3.55 Netscape Enterprise Server 3.6 SP2 Netscape Enterprise Server 3.6 Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 |
Exploit / POC
Multiple Vendor PKCS#1 Vulnerability
x
x
Solution / Fix
Multiple Vendor PKCS#1 Vulnerability
Solution:
Vendors of SSL enabled servers have supplied patches for their respective servers. A number of references have been cited below, otherwise contact your vendor.
Microsoft: http://support.microsoft.com/support/kb/articles/q148/4/27.asp
Netscape: http://help.netscape.com/products/servers/ssldiscovery/index.html
SSLeay: http://www.ssleay.org/announce/pkcs1.html
Open Market: http://www.openmarket.com/security
C2Net: http://www.c2net.org
Microsoft IIS 4.0
Microsoft Site Server Commerce Edition 3.0 i386
Microsoft IIS 3.0
Microsoft Exchange Server 5.5
Microsoft Site Server 3.0 i386
Microsoft Exchange Server 5.0
Solution:
Vendors of SSL enabled servers have supplied patches for their respective servers. A number of references have been cited below, otherwise contact your vendor.
Microsoft: http://support.microsoft.com/support/kb/articles/q148/4/27.asp
Netscape: http://help.netscape.com/products/servers/ssldiscovery/index.html
SSLeay: http://www.ssleay.org/announce/pkcs1.html
Open Market: http://www.openmarket.com/security
C2Net: http://www.c2net.org
Microsoft IIS 4.0
-
Microsoft Generic SSL (PCT/TLS) Updates for IIS and Microsoft Internet Products (Q148427)
http://support.microsoft.com/default.aspx?scid=kb;en-us;148427&sd=tech
Microsoft Site Server Commerce Edition 3.0 i386
-
Microsoft Generic SSL (PCT/TLS) Updates for IIS and Microsoft Internet Products (Q148427)
http://support.microsoft.com/default.aspx?scid=kb;en-us;148427&sd=tech
Microsoft IIS 3.0
-
Microsoft Generic SSL (PCT/TLS) Updates for IIS and Microsoft Internet Products (Q148427)
http://support.microsoft.com/default.aspx?scid=kb;en-us;148427&sd=tech
Microsoft Exchange Server 5.5
-
Microsoft Generic SSL (PCT/TLS) Updates for IIS and Microsoft Internet Products (Q148427)
http://support.microsoft.com/default.aspx?scid=kb;en-us;148427&sd=tech
Microsoft Site Server 3.0 i386
-
Microsoft Generic SSL (PCT/TLS) Updates for IIS and Microsoft Internet Products (Q148427)
http://support.microsoft.com/default.aspx?scid=kb;en-us;148427&sd=tech
Microsoft Exchange Server 5.0
-
Microsoft Generic SSL (PCT/TLS) Updates for IIS and Microsoft Internet Products (Q148427)
http://support.microsoft.com/default.aspx?scid=kb;en-us;148427&sd=tech