|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
OpenCA contains multiple flaws that may allow revoked or expired certificates to be accepted as valid. The issue is triggered because OpenCA fails to properly use the correct certificate in a chain to validate the certificate's serial. It is possible that the flaw may allow revoked/invalid keys being accepted, resulting in unauthorized access or a loss of confidentiality and/or integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Cryptographic
Impact:
Loss of Integrity
|
|
Technical |
The vulnerabilities are caused due to errors in the regular expressions in "OpenCA::PKCS7", and in the "crypto-utils.lib" library when creating X.509 objects and when checking serials of certificates used for creating a PKCS#7 signature.
|
|
Solution |
Upgrade to version 0.9.1.4 or higher, as it has been reported to fix this vulnerability. OpenCA has also released patches that address this issue.
|
|
Products |
|
OpenCA
 |
0.9.1.3 |
|
|
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|