English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

OpenSSL Two Vulnerabilities


Secunia ID

SA37291

CVE-ID

CVE-2009-3245, CVE-2009-3555

Release Date

06 Nov 2009

Last Change

03 Mar 2010

Criticality

Less Critical

Solution Status

Vendor Patch

Software

OpenSSL 0.9.x

Where

From remote

Impact
Manipulation of data

This includes vulnerabilities where a user or a remote attacker can manipulate local data on a system, but not necessarily be able to gain escalated privileges or system access.

The most frequent type of vulnerabilities with this impact are SQL-injection vulnerabilities, where a malicious user or person can manipulate SQL queries.

Unknown

Covers various weaknesses, security issues, and vulnerabilities not covered by the other impact types, or where the impact isn't known due to insufficient information from vendors and researchers.

Description

Two vulnerabilities have been reported in OpenSSL, where one has unknown impacts and the other can be exploited by malicious people to manipulate certain data.

1) A vulnerability is caused due to an error in the TLS protocol while handling session re-negotiations. This can be exploited to insert arbitrary plaintext before data sent by a legitimate client in an existing TLS session via Man-in-the-Middle (MitM) attacks.

Successful exploitation may allow e.g. sending an arbitrary HTTP request under an authenticated context if certificate-based authentication is used by the server.

2) A vulnerability is caused due to the library not properly verifying the return value of the "bn_wexpand()" function.

Solution

Update to version 0.9.8m.

Reported by

1) Independently discovered by Marsh Ray, PhoneFactor and Martin Rex.
2) Martin Olsson and Neel Mehta

Original Advisory

OpenSSL:
http://openssl.org/news/secadv_20091111.txt
http://archive.netbsd.se/?ml=openssl-announce&a=2010-02&m=12477250
http://rt.openssl.org/Ticket/Display.html?id=2111&user=guest&pass=guest

Martin Rex:
http://www.ietf.org/mail-archive/web/tls/current/msg03928.html

PhoneFactor:
http://extendedsubset.com/?p=8