Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with duplicate IDs.
References
Link Resource
http://blog.sec-consult.com/2017/06/german-e-government-details-vulnerabilities.html Technical Description Third Party Advisory
http://seclists.org/fulldisclosure/2017/Jun/44 Mailing List Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-06-30T12:00:00

Updated: 2017-06-30T11:57:01

Reserved: 2017-06-28T00:00:00


Link: CVE-2017-10669

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-06-30T12:29:00.260

Modified: 2017-07-06T17:58:48.303


Link: CVE-2017-10669

JSON object: View

cve-icon Redhat Information

No data.

CWE