Back to search
CVE-2002-1446
Published: Sep 1, 2004
Modified: Aug 8, 2024
PUBLISHED
Description
The error checking routine used for the C_Verify call on a symmetric verification key in the nCipher PKCS#11 library 1.2.0 and later returns the CKR_OK status even when it detects an invalid signature, which could allow remote attackers to modify or forge messages.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
ncipher-cverify-improper-verification(9895)
vdb-entry
x_refsource_XF
5498
vdb-entry
x_refsource_BID
http://www.ncipher.com/support/advisories/advisory5_c_verify.html
x_refsource_CONFIRM
20020819 nCipher Advisory #5: C_Verify validates incorrect symmetric signatures
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now