CVE-2014-1568
published 2014-09-25CVE-2014-1568: Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
16.17%
96.6th percentile
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
Affected
168 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| axtls_project | axtls | <= 2.1.3 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nss | < nss 2:3.17.1-1 (bookworm) | nss 2:3.17.1-1 (bookworm) |
| debian | strongswan | < strongswan 5.7.0-1 (bookworm) | strongswan 5.7.0-1 (bookworm) |
| chrome | <= 37.0.2062.120 | — | |
| chrome | <= 37.0.2062.103 | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| chrome | — | — | |
| mozilla | firefox | <= 32.0 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox_esr | — | — |
| mozilla | network_security_services | <= 3.16.2.0 | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
| mozilla | network_security_services | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7399-wc2p-9q6p: Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-17
CVE-2014-1568 [HIGH] GHSA-7399-wc2p-9q6p: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
GHSA
GHSA-g43p-7j43-jpj7: In sig_verify() in x509
ghsa_unreviewed·2022-05-14·CVSS 5.0
CVE-2018-16253 [MEDIUM] CWE-347 GHSA-g43p-7j43-jpj7: In sig_verify() in x509
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not properly verify the ASN.1 metadata. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation through fake X.509 certificates. This is an even more permissive variant of CVE-2006-4790 and CVE-2014-1568.
GHSA
GHSA-ff5x-x5ch-2x28: In verify_emsa_pkcs1_signature() in gmp_rsa_public_key
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2018-16152 [MEDIUM] CWE-347 GHSA-ff5x-x5ch-2x28: In verify_emsa_pkcs1_signature() in gmp_rsa_public_key
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication. This is a variant of CVE-2006-4790 and CVE-2014-1568.
OSV
CVE-2018-16152: In verify_emsa_pkcs1_signature() in gmp_rsa_public_key
osv·2018-09-26·CVSS 5.0
CVE-2018-16152 [MEDIUM] CVE-2018-16152: In verify_emsa_pkcs1_signature() in gmp_rsa_public_key
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication. This is a variant of CVE-2006-4790 and CVE-2014-1568.
OSV
CVE-2014-1568: Mozilla Network Security Services (NSS) before 3
osv·2014-09-25·CVSS 7.5
CVE-2014-1568 [HIGH] CVE-2014-1568: Mozilla Network Security Services (NSS) before 3
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
Red Hat
strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
vendor_redhat·2018-09-24·CVSS 5.0
CVE-2018-16152 [MEDIUM] CWE-287 strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication. This is a variant of CVE-2006-4790 and CVE-2014-1568.
Package: strongimcv (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2018-16152: strongswan - In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in st...
vendor_debian·2018·CVSS 5.0
CVE-2018-16152 [MEDIUM] CVE-2018-16152: strongswan - In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in st...
In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication. This is a variant of CVE-2006-4790 and CVE-2014-1568.
Scope: local
bookworm: resolved (fixed in 5.7.0-1)
bullseye: resolved (fixed in 5.7.0-1)
forky: resolved (fixed in 5.7.0-1)
sid: resolved (fixed in 5.7.0-1)
trixie: resolved (fixed in 5.7.0-1)
Ubuntu
NSS vulnerability
vendor_ubuntu·2014-09-24
CVE-2014-1568 NSS vulnerability
Title: NSS vulnerability
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
Antoine Delignat-Lavaud and others discovered that NSS incorrectly handled
parsing ASN.1 values. An attacker could use this issue to forge RSA
certificates.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use NSS, such as Evolution and Chromium, to make all the necessary
changes.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2014-09-24
CVE-2014-1568 Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
Antoine Delignat-Lavaud and others discovered that NSS incorrectly handled
parsing ASN.1 values. An attacker could use this issue to forge RSA
certificates.
Instructions: After a standard system update you need to restart Firefox to make
all the necessary changes.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2014-09-24
CVE-2014-1568 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
USN-2360-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Thunderbird.
Original advisory details:
Antoine Delignat-Lavaud and others discovered that NSS incorrectly handled
parsing ASN.1 values. An attacker could use this issue to forge RSA
certificates.
Instructions: After a standard system update you need to restart Thunderbird to make
all the necessary changes.
Red Hat
nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)
vendor_redhat·2014-09-24·CVSS 7.5
CVE-2014-1568 [HIGH] CWE-347 nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)
nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One) input from certain RSA signatures. A remote attacker could use
Debian
CVE-2014-1568: nss - Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, a...
vendor_debian·2014·CVSS 7.5
CVE-2014-1568 [HIGH] CVE-2014-1568: nss - Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, a...
Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X, and Google Chrome OS before 37.0.2062.120, does not properly parse ASN.1 values in X.509 certificates, which makes it easier for remote attackers to spoof RSA signatures via a crafted certificate, aka a "signature malleability" issue.
Scope: local
bookworm: resolved (fixed in 2:3.17.1-1)
bullseye: resolved (fixed in 2:3.17.1-1)
forky: resolved (fixed in 2:3.17.1-1)
sid: resolved (fixed in 2:3.17.1-1)
trixie: resolved (fixed in 2:3.17.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16152 strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
bugzilla·2018-10-03·CVSS 5.0
CVE-2018-16152 [MEDIUM] CVE-2018-16152 strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
CVE-2018-16152 strongswan: authentication bypass in verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c
A flaw was found in strongSwan 4.x and 5.x before 5.7.0. In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used, which could lead to impersonation when only an RSA signature is used for IKEv2 authentication. This is a variant of CVE-2006-4790 and CVE-2014-1568.
References:
https://www.strongswan.org/blog/2018/09/24/strongswan-vulnerability-(cve-2018-16151,-cve-2018-16152).html
Discussion:
Created strongswan tracking bugs
Bugzilla
CVE-2014-1569 nss: QuickDER decoder length issue
bugzilla·2014-12-15·CVSS 7.5
CVE-2014-1569 [HIGH] CVE-2014-1569 nss: QuickDER decoder length issue
CVE-2014-1569 nss: QuickDER decoder length issue
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-1569 to
the following vulnerability:
Name: CVE-2014-1569
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1569
Assigned: 20140116
Reference: http://www.intelsecurity.com/resources/wp-berserk-analysis-part-1.pdf
Reference: https://www.imperialviolet.org/2014/09/26/pkcs1.html
Reference: https://www.reddit.com/r/netsec/comments/2hd1m8/rsa_signature_forgery_in_nss/cksnr02
Reference: https://bugzilla.mozilla.org/show_bug.cgi?id=1064670
Reference: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.17.3_release_notes
The definite_length_decoder function in lib/util/quickder.c in Mozilla
Network Security Services (NSS) before 3.16.2.4 and 3.17.x befor
Bugzilla
CVE-2014-1568 nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73) [fedora-all]
bugzilla·2014-09-25·CVSS 7.5
CVE-2014-1568 [HIGH] CVE-2014-1568 nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73) [fedora-all]
CVE-2014-1568 nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2014-1568 nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)
bugzilla·2014-09-23·CVSS 7.5
CVE-2014-1568 [HIGH] CVE-2014-1568 nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)
CVE-2014-1568 nss: RSA PKCS#1 signature verification forgery flaw (MFSA 2014-73)
Antoine Delignat-Lavaud, security researcher at Inria Paris in team Prosecco, reported an issue in Network Security Services (NSS) libraries affecting all versions. He discovered that NSS is vulnerable to a variant of a signature forgery attack previously published by Daniel Bleichenbacher. This is due to lenient parsing of ASN.1 values involved in a signature and could lead to the forging of RSA certificates.
The Advanced Threat Research team at Intel Security also independently discovered and reported this issue.
Projects using NSS 3.17 should update the new 3.17.1 release.
External Reference:
http://www.mozilla.org/security/announce/2014/mfsa2014-73.html
Acknowledgements:
Red Hat would like to than
Bugzilla
PKCS#1 v1.5 RSA signature verification vulnerabilities due to ASN.1 parsing of DigestInfo
bugzilla·2014-09-18
[MEDIUM] PKCS#1 v1.5 RSA signature verification vulnerabilities due to ASN.1 parsing of DigestInfo
PKCS#1 v1.5 RSA signature verification vulnerabilities due to ASN.1 parsing of DigestInfo
From: Intel Product Security Incident Response Team
To: "'[email protected]'"
Subject: NSS Issue
------/------
Intel Security’s Advanced Threat Research (ATR) team has discovered a variant of the signature forgery attack previously published by Daniel Bleichenbacher, which enables this attack to be used to forge RSA certificates on multiple crypto libraries with incorrect implementation of verification. Due to the way affected libraries parse BER encoded fields, it is possible for an attacker to skip garbage bytes, enabling signature forgery. These attacks target RSA keys with a low exponent (such as 3). The vulnerability is due to the implementation of signature checking in particular crypto lib
http://googlechromereleases.blogspot.com/2014/09/stable-channel-update-for-chrome-os_24.htmlhttp://googlechromereleases.blogspot.com/2014/09/stable-channel-update_24.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00039.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1307.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1354.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1371.htmlhttp://secunia.com/advisories/61540http://secunia.com/advisories/61574http://secunia.com/advisories/61575http://secunia.com/advisories/61576http://secunia.com/advisories/61583http://www.debian.org/security/2014/dsa-3033http://www.debian.org/security/2014/dsa-3034http://www.debian.org/security/2014/dsa-3037http://www.kb.cert.org/vuls/id/772676http://www.mozilla.org/security/announce/2014/mfsa2014-73.htmlhttp://www.novell.com/support/kb/doc.php?id=7015701http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/70116http://www.ubuntu.com/usn/USN-2360-1http://www.ubuntu.com/usn/USN-2360-2http://www.ubuntu.com/usn/USN-2361-1https://bugzilla.mozilla.org/show_bug.cgi?id=1064636https://bugzilla.mozilla.org/show_bug.cgi?id=1069405https://exchange.xforce.ibmcloud.com/vulnerabilities/96194https://security.gentoo.org/glsa/201504-01http://googlechromereleases.blogspot.com/2014/09/stable-channel-update-for-chrome-os_24.htmlhttp://googlechromereleases.blogspot.com/2014/09/stable-channel-update_24.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00036.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00039.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1307.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1354.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1371.htmlhttp://secunia.com/advisories/61540http://secunia.com/advisories/61574http://secunia.com/advisories/61575http://secunia.com/advisories/61576http://secunia.com/advisories/61583http://www.debian.org/security/2014/dsa-3033http://www.debian.org/security/2014/dsa-3034http://www.debian.org/security/2014/dsa-3037http://www.kb.cert.org/vuls/id/772676http://www.mozilla.org/security/announce/2014/mfsa2014-73.htmlhttp://www.novell.com/support/kb/doc.php?id=7015701http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.htmlhttp://www.securityfocus.com/bid/70116http://www.ubuntu.com/usn/USN-2360-1http://www.ubuntu.com/usn/USN-2360-2http://www.ubuntu.com/usn/USN-2361-1https://bugzilla.mozilla.org/show_bug.cgi?id=1064636https://bugzilla.mozilla.org/show_bug.cgi?id=1069405https://exchange.xforce.ibmcloud.com/vulnerabilities/96194https://security.gentoo.org/glsa/201504-01
2014-09-25
Published