OpenSSL hit by forgery bug

By Matthew Broersma, ZDNet UK
Monday, September 25, 2006 11:28 AM

Security researchers have demonstrated a way to bypass OpenSSL security restrictions by forging certain digital signatures, the OpenSSL project has warned. OpenSSL is used in many security products, secure Web servers and virtual private networks (VPNs).

SSL (secure sockets layer) is used to secure e-commerce transactions, among other purposes.

OpenSSL has released a new version fixing the problem, and urged users to upgrade or apply a patch.

The flaw only affects a particular type of signature--PKCS #1 v1.5 signatures--but these are used by some certificate authorities.

"If an RSA key with exponent 3 is used, it may be possible to forge a PKCS #1 v1.5 signature signed by that key," OpenSSL said in an advisory. "Since there are (certificate authorities) using exponent 3 in wide use, and PKCS #1 v1.5 is used in X.509 certificates, all software that uses OpenSSL to verify X.509 certificates is potentially vulnerable."

Versions of OpenSSL up to 0.9.7j and 0.9.8b are affected, according to the advisory.

The signature forgery technique was first demonstrated last month at the Crypto 2006 conference by Daniel Bleichenbacher, a cryptographer with Bell Labs, according to security firm Netcraft. OpenSSL credited Google Security with successfully forging various certificates and providing the fix.

OpenSSL is an open source implementation of the SSL and TLS protocols, with versions available for most Unix-like operating systems and Windows.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Five tips for tackling a one-time project

Tech Management

Don't let a one-time project derail your career. An IT consultant shares tips on how to successfully manage a "once-in-a-career" event.


Read more »



Open source blog reloaded!

Blog thumbnail

This is with great pleasure that this "little corner of the Web" is resuming activities through another member of the (now famous ;-)) Beijing Linux User Group (BLUG) doing the..... by Fred Muller

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. google inc.
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web