Incorrect Certificate Validation in Java Secure Socket Extension

From: Alex Loots (a.loots@itsec-ss.nl)
Date: 01/28/03

  • Next message: Michael Brown: "ProxyView default undocumented password"
    Date: Tue, 28 Jan 2003 09:04:29 +0100
    From: Alex Loots <a.loots@itsec-ss.nl>
    To: "bugtraq@securityfocus.com" <bugtraq@securityfocus.com>
    
    

    According to SUN it has been reported that: "the Java Secure Socket
    Extension (JSSE) may incorrectly validate the digital certificate of a
    web site. This may result in untrustworthy web sites being
    authenticated for SSL transactions. The Java Plug-in and Java Web Start
    may incorrectly validate the digital certificates of signed JAR files.
    This may result in untrustworthy code being executed as trusted code."

    From the JSSE changelog: "If an SSLContext was initialized
    (SSLContext.init()) with an instance of the X509TrustManager
    implementation, JSSE 1.0.3 incorrectly called the isClientTrusted()
    method when making server trust decisions."

    The SUN bulletin:
    http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F50081&zone_32=category%3Asecurity

    The changelog Java(tm) Secure Socket Extension 1.0.3_01 mentions this
    vulnerability
    http://java.sun.com/products/jsse/CHANGES.txt

    -- 
    -Alex
    


    Relevant Pages

    • Re: RubyOnRails and Intraweb
      ... What does AJAX or a Web site have to do with sticking design in a Database? ... Another difference might be if you are using a Client/Server approach, where the Client is a true rich client running inside/outside the browser, and downloaded to the local machine and using HTTP as the transfer protocol, much like a Flash, Java Applet, or Java Web Start application. ... I still do not know how you can control the basic framework they are using, because I do not know what the basic framework is. ... Click on the XHTML tags, add your Java Script code, code your JS functions, point to your server, and then within the IDE, debug the application; ...
      (borland.public.delphi.non-technical)
    • Re: I need Intel iMac Info
      ... As with most things on the Mac, ... I don't necessarily need to a web site design program as all of the ... If it will work on the Intel iMac I would be happy to pay the steep ... >> It is crucial that any new machine within our office have Java ...
      (comp.sys.mac.system)
    • Re: I need Intel iMac Info
      ... > We use an OS/2 computer to pipe MP3 music files through the office ... > web site service. ... > these web site directories under an OS X operating system on an iMac? ... > It is crucial that any new machine within our office have Java ...
      (comp.sys.mac.system)
    • Re: Cant access this web site :(
      ... The Problem is that When I try to access a web site ... Another way of accessing this same java control is through ... opens but the java control still doesn't come up. ... v: dump thread stack ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: I need Intel iMac Info
      ... > web site service. ... > these web site directories under an OS X operating system on an iMac? ... I need to convert those VHS videos over to ... > It is crucial that any new machine within our office have Java ...
      (comp.sys.mac.system)