|
I see the vendor (IBM) disclosed these, and listed V5R1M0 as the release. jim ----- Original Message ----- From: "David Gibbs" <david@xxxxxxxxxxxx> To: "Midrange Systems Technical Discussion" <midrange-l@xxxxxxxxxxxx>; <security400@xxxxxxxxxxxx> Sent: Friday, September 09, 2005 7:05 PM Subject: IBM OS/400 Multiple OSP-CERT Vulnerabilities > I found this while stumbling around today ... > > http://www.securityfocus.com/bid/14800/info > > IBM OS/400 osp-cert is susceptible to multiple vulnerabilities. > > The first identified vulnerability is a flaw in local Certificate > Authority certificates. During the creation of these certificates, X.509 > basic constraints are not added. Since the local Certificate Authority > certificates are not properly identified as valid Certificate > Authorities, the proper validation of these certificates is impossible, > as is the verification of certificate chains that are derived from it. > > The next issue is a failure of the application to properly return > renewed certificates once they have been made available. This issue is > due to a failure of the application to properly notice altered > certificate store files during operation. > > There are also multiple unspecified ASN.1 parsing vulnerabilities. No > further information about these issues are currently available. > > These issues allow attackers to potentially subvert, bypass, or possibly > alter the security properties of the cryptographic software. The exact > impact and possible attack scenarios are not known at this time. > > -- > This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list > To post a message email: MIDRANGE-L@xxxxxxxxxxxx > To subscribe, unsubscribe, or change list options, > visit: http://lists.midrange.com/mailman/listinfo/midrange-l > or email: MIDRANGE-L-request@xxxxxxxxxxxx > Before posting, please take a moment to review the archives > at http://archive.midrange.com/midrange-l. > >
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.