OpenCA Crypto-Utils.Lib Signature Verification Vulnerability

OpenCA have reported a vulnerability in the crypto-utils.lib library. The flaw has been discovered in the manner in which an affected function operates, the affected function only performs a comparison on the base of the serial of the associated certificate. This may inadvertently lead to the acceptance of a malicious certificate.


 

Privacy Statement
Copyright 2010, SecurityFocus