CVE-2017-10669

Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with duplicate IDs.
References
Link Resource
http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html Technical Description Third Party Advisory
http://seclists.org/fulldisclosure/2017/Jun/44 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xoev:osci_transport_library:1.6:*:*:*:.net:*:*:*
cpe:2.3:a:xoev:osci_transport_library:1.6.1:*:*:*:java:*:*:*

History

No history.

Information

Published : 2017-06-30 12:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-10669

Mitre link : CVE-2017-10669

CVE.ORG link : CVE-2017-10669


JSON object : View

Products Affected

xoev

  • osci_transport_library
CWE
CWE-347

Improper Verification of Cryptographic Signature