× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



I see the vendor (IBM) disclosed these, and listed V5R1M0 as
the release.
jim

----- Original Message ----- 
From: "David Gibbs" <david@xxxxxxxxxxxx>
To: "Midrange Systems Technical Discussion" <midrange-l@xxxxxxxxxxxx>;
<security400@xxxxxxxxxxxx>
Sent: Friday, September 09, 2005 7:05 PM
Subject: IBM OS/400 Multiple OSP-CERT Vulnerabilities


> I found this while stumbling around today ...
>
> http://www.securityfocus.com/bid/14800/info
>
>  IBM OS/400 osp-cert is susceptible to multiple vulnerabilities.
>
> The first identified vulnerability is a flaw in local Certificate
> Authority certificates. During the creation of these certificates, X.509
> basic constraints are not added. Since the local Certificate Authority
> certificates are not properly identified as valid Certificate
> Authorities, the proper validation of these certificates is impossible,
> as is the verification of certificate chains that are derived from it.
>
> The next issue is a failure of the application to properly return
> renewed certificates once they have been made available. This issue is
> due to a failure of the application to properly notice altered
> certificate store files during operation.
>
> There are also multiple unspecified ASN.1 parsing vulnerabilities. No
> further information about these issues are currently available.
>
> These issues allow attackers to potentially subvert, bypass, or possibly
> alter the security properties of the cryptographic software. The exact
> impact and possible attack scenarios are not known at this time.
>
> -- 
> This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing
list
> To post a message email: MIDRANGE-L@xxxxxxxxxxxx
> To subscribe, unsubscribe, or change list options,
> visit: http://lists.midrange.com/mailman/listinfo/midrange-l
> or email: MIDRANGE-L-request@xxxxxxxxxxxx
> Before posting, please take a moment to review the archives
> at http://archive.midrange.com/midrange-l.
>
>



As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:
Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.