CERT-In Advisory
CIAD-2011-0062
Fraudulent Digital Certificate Vulnerability
Original Issue Date: November 11, 2011
Severity Rating: High
Systems Affected
- Windows XP SP3
- Windows XP Professional x64 Edition SP2
- Windows Server 2003 SP2
- Windows Server 2003 x64 Edition SP2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista SP2
- Windows Vista x64 Edition SP2
- Windows Server 2008 for 32-bit Systems SP2 (Server Core installation affected)
- Windows Server 2008 for x64-based Systems SP2 (Server Core installation affected)
- Windows Server 2008 for Itanium-based Systems SP2
- Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems SP1
- Windows 7 for x64-based Systems and Windows 7 for x64-based Systems SP1
- Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems SP1 (Server Core installation affected)
- Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems SP1
- Firefox versions prior to 3.6.24
- Firefox versions prior to 8
Component Affected
- Windows Mobile 6.x
- Windows Phone 7
- Windows Phone 7.5
Overview
Fraudulent digital certificates were issued by a certificate authority, which could be exploited by remote attackers to perform man-in-the-middle attacks, spoof content, or perform phishing attacks against all Web browser users.
Description
DigiCert Sdn. Bhd, issued 22 certificates with weak 512 bit keys. These cryptographically weak keys allowed some of the certificates to be duplicated and used in a fraudulent manner. A remote attacker could use one of these weak certificates to impersonate the legitimate owners through a man-in-the-middle attack (MITM), spoof content, or perform phishing attacks against all Web browser users.
Solution
Multiple vendors have released security advisories and updates.
Vendor Information
Microsoft Corporation
http://technet.microsoft.com/en-us/security/advisory/2641690
Mozilla
http://blog.mozilla.com/security/2011/11/03/revoking-trust-in-digicert-sdn-bhd-intermediate-certificate-authority/
References
Microsoft Corporation
http://technet.microsoft.com/en-us/security/advisory/2641690
Mozilla
http://blog.mozilla.com/security/2011/11/03/revoking-trust-in-digicert-sdn-bhd-intermediate-certificate-authority/
Entrust
http://www.entrust.net/advisories/malaysia.htm
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|