First published: Thu Aug 01 2002(Updated: )
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ncipher Pkcs 11 Library | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.