Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200609-05 ] OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Advocate
Advocate


Joined: 12 May 2004
Posts: 2663

PostPosted: Thu Sep 07, 2006 9:26 pm    Post subject: [ GLSA 200609-05 ] OpenSSL, AMD64 x86 emulation base librari Reply with quote

Gentoo Linux Security Advisory

Title: OpenSSL, AMD64 x86 emulation base libraries: RSA signature forgery (GLSA 200609-05)
Severity: normal
Exploitable: remote
Date: September 07, 2006
Updated: September 08, 2006
Bug(s): #146375, #146438
ID: 200609-05

Synopsis

OpenSSL fails to properly validate PKCS #1 v1.5 signatures.

Background

OpenSSL is a toolkit implementing the Secure Sockets Layer, Transport Layer Security protocols and a general-purpose cryptography library. The x86 emulation base libraries for AMD64 contain a vulnerable version of OpenSSL.

Affected Packages

Package: dev-libs/openssl
Vulnerable: < 0.9.7k
Unaffected: >= 0.9.7k
Architectures: All supported architectures

Package: app-emulation/emul-linux-x86-baselibs
Vulnerable: < 2.5.2
Unaffected: >= 2.5.2
Architectures: amd64


Description

Daniel Bleichenbacher discovered that it might be possible to forge signatures signed by RSA keys with the exponent of 3.

Impact

Since several CAs are using an exponent of 3 it might be possible for an attacker to create a key with a false CA signature.

Workaround

There is no known workaround at this time.

Resolution

All OpenSSL users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-libs/openssl-0.9.7k"
All AMD64 x86 emulation base libraries users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-emulation/emul-linux-x86-baselibs-2.5.2"


References

CVE-2006-4339


Last edited by GLSA on Sat Sep 09, 2006 4:17 am; edited 1 time in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum