Oracle iPlanet Web Server 7.0.x < 7.0.21 NSS Signature Verification Vulnerability

high Nessus Plugin ID 82995

Synopsis

The remote web server is affected by a signature forgery vulnerability.

Description

According to its self-reported version, the Oracle iPlanet Web Server (formerly known as Sun Java System Web Server) running on the remote host is 7.0.x prior to 7.0.21. It is, therefore, affected by a flaw in the Network Security Services (NSS) library due to improper parsing of ASN.1 values in an RSA signature. A man-in-the-middle attacker, using a crafted certificate, can exploit this to forge RSA signatures, such as SSL certificates.

Solution

Upgrade to Oracle iPlanet Web Server 7.0.21 or later.

See Also

http://www.nessus.org/u?56618dc1

Plugin Details

Severity: High

ID: 82995

File Name: sun_java_web_server_7_0_21.nasl

Version: 1.12

Type: remote

Family: Web Servers

Published: 4/22/2015

Updated: 11/22/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2014-1568

Vulnerability Information

CPE: cpe:/a:oracle:iplanet_web_server, cpe:/a:mozilla:network_security_services

Required KB Items: installed_sw/Oracle iPlanet Web Server/

Exploit Ease: No known exploits are available

Patch Publication Date: 4/14/2015

Vulnerability Publication Date: 9/24/2014

Reference Information

CVE: CVE-2014-1568

BID: 70116

CERT: 772676