Overview
Some applications that perform X.509 certificate verification may be vulnerable to signature processing problems that lead to resource exhaustion. This vulnerability may cause a denial of service.
Description
Included in X.509 certificates are public keys used for digital signature verification. Choosing very large values for the public exponent and public modulus associated with an RSA public key may cause the verification of that key to require large amounts of system resources. According to NISCC: ...by choosing much larger values for [the public exponent and the public modulus], it may be possible to cause the verification process to consume large amounts of system resources and hence result in a denial-of-service condition. |
Impact
A remote, unauthenticated attacker could consume large amounts of system resources on an affected device, thereby creating a denial of service. |
Solution
Upgrade or apply a patch from the vendor |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2531
- http://www.hornik.sk/SA/SA-20040802.txt
- http://www.gnu.org/software/gnutls/
- http://www.securitytracker.com/alerts/2004/Aug/1010838.html
- http://www.niscc.gov.uk/niscc/docs/re-20060928-00661.pdf?lang=en
- http://www.openssl.org/news/secadv_20060928.txt
- http://secunia.com/advisories/23280/
- http://secunia.com/advisories/23309/
- http://secunia.com/advisories/23351/
- http://www.securityfocus.com/bid/22083
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102668-1
Acknowledgements
NISCC credits Dr. Stephen N. Henson for reporting this vulnerability. This issue was originally reported in GnuTLS by Patrik Hornik.
This document was written by Chris Taschner.
Other Information
CVE IDs: | CVE-2006-2940 |
Severity Metric: | 7.92 |
Date Public: | 2004-08-02 |
Date First Published: | 2006-09-28 |
Date Last Updated: | 2007-02-09 21:30 UTC |
Document Revision: | 63 |