Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with duplicate IDs.
References
Link | Resource |
---|---|
http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html | Technical Description Third Party Advisory |
http://seclists.org/fulldisclosure/2017/Jun/44 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2017-06-30 12:29
Updated : 2017-07-06 17:58
NVD link : CVE-2017-10669
Mitre link : CVE-2017-10669
CVE.ORG link : CVE-2017-10669
JSON object : View
Products Affected
xoev
- osci_transport_library
CWE
CWE-347
Improper Verification of Cryptographic Signature