Find Articles in:
All
Business
Reference
Technology
News
Lifestyle

MS02-050: certificate validation flaw could enable identity spoofing. (Microsoft).(Brief Article)

Information Systems Auditor, October, 2002

Content provided in partnership with HighBeam Research

Issue

The IETF Profile of the X.509 certificate standard defines several optional fields that can be included in a digital certificate. One of these is the Basic Constraints field, which indicates the maximum allowable length of the certificate's chain and whether the certificate is a Certificate Authority or an end-entity certificate. However, the application program interfaces (APIs) within CryptoAPI that construct and validate certificate chains --CertGetCertificateChain(), CertVerifyCertificateChainPolicy() and WinVerifyTrust()--do not check the Basic Constraints field. The same flaw, unrelated to CryptoAPI, is also present in several Microsoft products for Macintosh.

The vulnerability could enable attackers who had a valid end-entity certificate...

 

BNET TalkbackShare your ideas and expertise on this topic

The following tags are supported in BNET comments:
<b></b> <i></i> <u></u> <pre></pre>

Leave a Reply

  1. You are currently a guest | Login?
advertisement
Go
advertisement
  • Click Here
  • Click Here
advertisement