CVE-2017-10669

Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with duplicate IDs.
References
Link Resource
http://seclists.org/fulldisclosure/2017/Jun/44 Mailing List Third Party Advisory
http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html Technical Description Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xoev:osci_transport_library:1.6:*:*:*:.net:*:*:*
cpe:2.3:a:xoev:osci_transport_library:1.6.1:*:*:*:java:*:*:*

Information

Published : 2017-06-30 05:29

Updated : 2017-07-06 10:58


NVD link : CVE-2017-10669

Mitre link : CVE-2017-10669


JSON object : View

CWE
CWE-347

Improper Verification of Cryptographic Signature

Advertisement

dedicated server usa

Products Affected

xoev

  • osci_transport_library