[NT] Security Flaw in Indentix BioLogon Client for Windows

From: support@securiteam.com
Date: 08/06/01


From: support@securiteam.com
To: list@securiteam.com
Subject: [NT] Security Flaw in Indentix BioLogon Client for Windows
Message-Id: <20010806124509.D046213903@mail.der-keiler.de>
Date: Mon,  6 Aug 2001 14:45:09 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com

  Security Flaw in Indentix BioLogon Client for Windows
------------------------------------------------------------------------

SUMMARY

 <http://www.identix.com> Identix's BioLogon software is used as "glue" to
tie together various biometric devices to the Windows operating system.
The BioLogon client works with smart cards, fingerprint readers, and other
devices that interact with Windows.

A security vulnerability in the product allows attackers to bypass the
identification protection used by the program whenever this product is
installed on a "multi-monitor" (multi screen) system.

DETAILS

Vulnerable systems:
BioLogon Client version 2.0

The security vulnerability exists when the software is installed onto a
Windows system that has more than one video card installed and the system
is doing "multi-monitor" with the built in virtual desktop software that
comes with Windows 98 SE and Windows 2000.

The problem is that the BioLogon client software attempts to harden the
screensaver password locking mechanism so that a biometric device is
needed to unlock the system. Unfortunately, the software only locks the
first screen (screen zero). No access is blocked from any other screen
(virtual desktop). Mouse, keyboard, and the screen can be used while
screen zero is locked. In fact, unless the mouse is on screen zero, the
biometric device will not recognize the fact it should inquire for input.

Vendor response:
Vendor has been contacted, their response was:
"Problem was noted and replicated but that it is a very low priority".

ADDITIONAL INFORMATION

The information has been provided by <mailto:Marc.DeBonis@VT.EDU> Marc
DeBonis.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Identix BioLogon Client security bug
    ... Identix BioLogon Client security bug ... Security flaw in Indentix BioLogon 2.0 Client for Windows ... to harden the screensaver password locking mechanism so ...
    (NT-Bugtraq)
  • Re: Problem with Virus killing computer
    ... screensaver settings and background image... ... restore your computer to a state prior ... windows XP security centre and I keep getting a bubble up saying "danger! ...
    (microsoft.public.windowsxp.help_and_support)
  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)
  • Re: The Myth of the secure Mac
    ... OEM Windows XP Home goes for a bit under $100. ... >> secure than Home. ... Though this really has nothing to do with security. ... Microsoft counts on third-party developers to provide more ...
    (comp.sys.mac.advocacy)