openSkat VTMF weak encryption

openskat-vtmf-weak-encryption (18049) The risk level is classified as LowLow Risk

Description:

openSkat uses a weak encryption scheme when generating public keys, caused by a vulnerability in the CheckGroup function in the VTMF implementation. A remote attacker could use this vulnerability to determine the private key.


Consequences:

Obtain Information

Remedy:

Upgrade to the latest version of openSkat (2.1 or later), available from the openSkat Web page. See References.

References:

  • openSkat Web page: openSkat.
  • BID-11667: OpenSkat Weak Encryption Key Generation Vulnerability
  • CVE-2004-2721: The CheckGroup function in openSkat VTMF before 2.1 generates public key pairs in which the p variable might not be prime, which allows remote attackers to determine the private key and decrypt messages.
  • OSVDB ID: 11652: openSkat VTMF CheckGroup() Randomization Error Private Key Disclosure
  • SECTRACK ID: 1012181: OpenSkat VTMF CheckGroup() Randomization Error May Let Remote Users Determine Private Keys

Platforms Affected:

  • openSkat openSkat prior to 2.1

Reported:

Nov 11, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page