5

CVE-2002-1446

The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NcipherPkcs 11 Library Version1.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.679
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2002-08/0172.html
http://www.iss.net/security_center/static/9895.php
http://www.ncipher.com/support/advisories/advisory5_c_verify.html
Patch
http://www.securityfocus.com/bid/5498