ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

OpenSSL hit by forgery bug

Matthew Broersma ZDNet.co.uk

Published: 22 Sep 2006 16:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security researchers have demonstrated a way to bypass OpenSSL security restrictions by forging certain digital signatures, the OpenSSL project has warned. OpenSSL is used in many security products, secure Web servers and virtual private networks (VPNs).

SSL (secure sockets layer) is used to secure e-commerce transactions, among other purposes.

OpenSSL has released a new version fixing the problem, and urged users to upgrade or apply a patch.

The flaw only affects a particular type of signature — PKCS #1 v1.5 signatures — but these are used by some certificate authorities.

"If an RSA key with exponent 3 is used, it may be possible to forge a PKCS #1 v1.5 signature signed by that key," OpenSSL said in an advisory. "Since there are (certificate authorities) using exponent 3 in wide use, and PKCS #1 v1.5 is used in X.509 certificates, all software that uses OpenSSL to verify X.509 certificates is potentially vulnerable."

Versions of OpenSSL up to 0.9.7j and 0.9.8b are affected, according to the advisory.

The signature forgery technique was first demonstrated last month at the Crypto 2006 conference by Daniel Bleichenbacher, a cryptographer with Bell Labs, according to security firm Netcraft. OpenSSL credited Google Security with successfully forging various certificates and providing the fix.

OpenSSL is an open source implementation of the SSL and TLS protocols, with versions available for most Unix-like operating systems and Windows.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
196 out of 300 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment