Advertisement
Promo

Security threats Toolkit

OpenSSL hit by forgery bug

Matthew Broersma ZDNet.co.uk

Published: 22 Sep 2006 16:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security researchers have demonstrated a way to bypass OpenSSL security restrictions by forging certain digital signatures, the OpenSSL project has warned. OpenSSL is used in many security products, secure Web servers and virtual private networks (VPNs).

SSL (secure sockets layer) is used to secure e-commerce transactions, among other purposes.

OpenSSL has released a new version fixing the problem, and urged users to upgrade or apply a patch.

The flaw only affects a particular type of signature — PKCS #1 v1.5 signatures — but these are used by some certificate authorities.

"If an RSA key with exponent 3 is used, it may be possible to forge a PKCS #1 v1.5 signature signed by that key," OpenSSL said in an advisory. "Since there are (certificate authorities) using exponent 3 in wide use, and PKCS #1 v1.5 is used in X.509 certificates, all software that uses OpenSSL to verify X.509 certificates is potentially vulnerable."

Versions of OpenSSL up to 0.9.7j and 0.9.8b are affected, according to the advisory.

The signature forgery technique was first demonstrated last month at the Crypto 2006 conference by Daniel Bleichenbacher, a cryptographer with Bell Labs, according to security firm Netcraft. OpenSSL credited Google Security with successfully forging various certificates and providing the fix.

OpenSSL is an open source implementation of the SSL and TLS protocols, with versions available for most Unix-like operating systems and Windows.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
196 out of 300 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters