OpenSSL hit by forgery bug

By Matthew Broersma, ZDNet UK
Monday, September 25, 2006 11:28 AM

Security researchers have demonstrated a way to bypass OpenSSL security restrictions by forging certain digital signatures, the OpenSSL project has warned. OpenSSL is used in many security products, secure Web servers and virtual private networks (VPNs).

SSL (secure sockets layer) is used to secure e-commerce transactions, among other purposes.

OpenSSL has released a new version fixing the problem, and urged users to upgrade or apply a patch.

The flaw only affects a particular type of signature--PKCS #1 v1.5 signatures--but these are used by some certificate authorities.

"If an RSA key with exponent 3 is used, it may be possible to forge a PKCS #1 v1.5 signature signed by that key," OpenSSL said in an advisory. "Since there are (certificate authorities) using exponent 3 in wide use, and PKCS #1 v1.5 is used in X.509 certificates, all software that uses OpenSSL to verify X.509 certificates is potentially vulnerable."

Versions of OpenSSL up to 0.9.7j and 0.9.8b are affected, according to the advisory.

The signature forgery technique was first demonstrated last month at the Crypto 2006 conference by Daniel Bleichenbacher, a cryptographer with Bell Labs, according to security firm Netcraft. OpenSSL credited Google Security with successfully forging various certificates and providing the fix.

OpenSSL is an open source implementation of the SSL and TLS protocols, with versions available for most Unix-like operating systems and Windows.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Reviewing scheduled task inventory for Windows Server 2008 R2

Windows Server

Default installations of Windows Server 2008 R2 enumerate a number of default scheduled tasks, many of which you may not need.


Read more »



Don't CC me, I'll CC you

Blog thumbnail

Carbon paper fascinated me when I was younger. Write once, get two copies. What a great invention and work tool, I thought.

Then came e-mail, and making carbon copies of important..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web