Bug 570678 (CVE-2010-0055) - CVE-2010-0055 xar: signature bypass vulnerability
Summary: CVE-2010-0055 xar: signature bypass vulnerability
Status: CLOSED ERRATA
Alias: CVE-2010-0055
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL: http://web.nvd.nist.gov/view/vuln/det...
Whiteboard: impact=moderate,source=vendor-sec,rep...
Keywords: Security
Depends On: 570679
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-03-05 01:36 UTC by Vincent Danen
Modified: 2015-07-31 06:25 UTC (History)
1 user (show)

(edit)
Clone Of:
(edit)
Last Closed: 2010-07-08 16:25:58 UTC


Attachments (Terms of Use)

Description Vincent Danen 2010-03-05 01:36:43 UTC
Braden Thomas of the Apple Security Team reported a signature verification bypass vulnerability in xar.  xar_open assumes that the checksum is stored at offset 0, however xar_signature_copy_signed_data uses the xar property "checksum/offset" to find the offset to the checksum when validating the signature.  Because of this, a modified xar archive can pass signature validation by putting the checksum for the modified TOC at offset 0, pointing "checksum/offset" to the non-modified checksum at a higher offset, and using the original, non-modified, signature.

The fix was incorported upstream with revision 225:

http://code.google.com/p/xar/source/detail?r=225

Comment 2 Vincent Danen 2010-03-05 01:40:58 UTC
This vulnerability affects all current releases of Fedora, as well as rawhide, EPEL4, and EPEL5.

Comment 3 Fedora Update System 2010-04-28 14:26:10 UTC
xar-1.5.2-6.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/xar-1.5.2-6.fc12

Comment 4 Fedora Update System 2010-04-28 14:26:15 UTC
xar-1.5.2-6.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/xar-1.5.2-6.fc13

Comment 5 Fedora Update System 2010-04-28 14:26:19 UTC
xar-1.5.2-6.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/xar-1.5.2-6.fc11

Comment 6 Fedora Update System 2010-04-28 14:26:23 UTC
xar-1.5.2-6.el5 has been submitted as an update for Fedora EPEL 5.
http://admin.fedoraproject.org/updates/xar-1.5.2-6.el5

Comment 7 Fedora Update System 2010-05-12 17:56:23 UTC
xar-1.5.2-6.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2010-05-12 17:59:54 UTC
xar-1.5.2-6.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 9 Fedora Update System 2010-05-12 18:01:23 UTC
xar-1.5.2-6.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Fedora Update System 2010-05-14 01:08:19 UTC
xar-1.5.2-6.el5 has been pushed to the Fedora EPEL 5 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.