First published: Thu Aug 01 2002(Updated: )
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ncipher PKCS #11 Library | =1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1446 is classified as a medium severity vulnerability due to its potential for message forgery.
To fix CVE-2002-1446, update the nCipher PKCS#11 library to a version where this vulnerability has been addressed.
CVE-2002-1446 affects the nCipher PKCS#11 library version 1.2.0 and later.
CVE-2002-1446 allows remote attackers to modify or forge messages due to improper error checking on a symmetric verification key.
Yes, CVE-2002-1446 can be exploited remotely, enabling attackers to forge signatures.