#VU20371 Improper Authentication in OpenPGP.js - CVE-2019-9153
Published: August 23, 2019
OpenPGP.js
ProtonMail
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due the software does not verify the signature type during verification of a message signature. A remote attacker can send a specially crafted message with replaced signatures with a "standalone" or "timestamp" signature and forge signed messages.
Remediation
External links
- https://github.com/openpgpjs/openpgpjs/pull/797/commits/327d3e5392a6f59a4270569d200c7f7a2bfc4cbc
- https://github.com/openpgpjs/openpgpjs/pull/816
- https://github.com/openpgpjs/openpgpjs/releases/tag/v4.2.0
- https://sec-consult.com/en/blog/advisories/multiple-vulnerabilities-in-openpgp-js/
- https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Mailvelope_Extensions/Mailv...