OpenCA Crypto-Utils.Lib Signature Verification Vulnerability
BID:9435
Info
OpenCA Crypto-Utils.Lib Signature Verification Vulnerability
| Bugtraq ID: | 9435 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2004-0004 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2004 12:00AM |
| Updated: | Jul 12 2009 02:06AM |
| Credit: | This vulnerability was announced by the vendor and is credited to Alexandru Matei. |
| Vulnerable: |
OpenCA OpenCA 0.9.1 -6 OpenCA OpenCA 0.9.1 -5 OpenCA OpenCA 0.9.1 -4 OpenCA OpenCA 0.9.1 -3 OpenCA OpenCA 0.9.1 -2 OpenCA OpenCA 0.9.1 -1 OpenCA OpenCA 0.9.1 OpenCA OpenCA 0.9 .0-2 OpenCA OpenCA 0.9 .0-1 OpenCA OpenCA 0.9 .0 |
| Not Vulnerable: |
OpenCA OpenCA 0.9.1 -7 |
Discussion
OpenCA Crypto-Utils.Lib Signature Verification Vulnerability
OpenCA have reported a vulnerability in the crypto-utils.lib library. The flaw has been discovered in the manner in which an affected function operates, the affected function only performs a comparison on the base of the serial of the associated certificate. This may inadvertently lead to the acceptance of a malicious certificate.
OpenCA have reported a vulnerability in the crypto-utils.lib library. The flaw has been discovered in the manner in which an affected function operates, the affected function only performs a comparison on the base of the serial of the associated certificate. This may inadvertently lead to the acceptance of a malicious certificate.
Exploit / POC
OpenCA Crypto-Utils.Lib Signature Verification Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenCA Crypto-Utils.Lib Signature Verification Vulnerability
Solution:
The vendor has released an upgrade to address this issue. Users are advised to apply the upgrade and use newer snapshots than openca-SNAP-20040114.tar.gz.
OpenCA OpenCA 0.9 .0
OpenCA OpenCA 0.9 .0-1
OpenCA OpenCA 0.9 .0-2
OpenCA OpenCA 0.9.1
OpenCA OpenCA 0.9.1 -1
OpenCA OpenCA 0.9.1 -2
OpenCA OpenCA 0.9.1 -3
Solution:
The vendor has released an upgrade to address this issue. Users are advised to apply the upgrade and use newer snapshots than openca-SNAP-20040114.tar.gz.
OpenCA OpenCA 0.9 .0
-
OpenCA openca-0.9.1-4.tar.gz
http://www.openca.org/cgi-bin/openca/downloads/sf-dl?name=openca-0.9.1 -4.tar.gz
OpenCA OpenCA 0.9 .0-1
-
OpenCA openca-0.9.1-4.tar.gz
http://www.openca.org/cgi-bin/openca/downloads/sf-dl?name=openca-0.9.1 -4.tar.gz
OpenCA OpenCA 0.9 .0-2
-
OpenCA openca-0.9.1-4.tar.gz
http://www.openca.org/cgi-bin/openca/downloads/sf-dl?name=openca-0.9.1 -4.tar.gz
OpenCA OpenCA 0.9.1
-
OpenCA openca-0.9.1-4.tar.gz
http://www.openca.org/cgi-bin/openca/downloads/sf-dl?name=openca-0.9.1 -4.tar.gz
OpenCA OpenCA 0.9.1 -1
-
OpenCA openca-0.9.1-4.tar.gz
http://www.openca.org/cgi-bin/openca/downloads/sf-dl?name=openca-0.9.1 -4.tar.gz
OpenCA OpenCA 0.9.1 -2
-
OpenCA openca-0.9.1-4.tar.gz
http://www.openca.org/cgi-bin/openca/downloads/sf-dl?name=openca-0.9.1 -4.tar.gz
OpenCA OpenCA 0.9.1 -3
-
OpenCA openca-0.9.1-4.tar.gz
http://www.openca.org/cgi-bin/openca/downloads/sf-dl?name=openca-0.9.1 -4.tar.gz
References
OpenCA Crypto-Utils.Lib Signature Verification Vulnerability
References:
References:
- OpenCA Homepage (OpenCA)
- OpenCA Security Advisory [16 January 2004] (OpenCA)
- [OpenCA Advisory] Vulnerability in signature verification. (Michael Bell
)