The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin MS02-050: Certificate Validation Flaw Could Enable Identity Spoofing (Q328145)
Time: 16:54 EST/21:54 GMT | News Source: Microsoft TechNet Security | Posted By: Byron Hinson

The IETF Profile of the X.509 certificate standard defines several optional fields that can be included in a digital certificate. One of these is the Basic Constraints field, which indicates the maximum allowable length of the certificate’s chain and whether the certificate is a Certificate Authority or an end-entity certificate. However, the APIs within CryptoAPI that construct and validate certificate chains (CertGetCertificateChain(), CertVerifyCertificateChainPolicy(), and WinVerifyTrust()) do not check the Basic Constraints field. The same flaw, unrelated to CryptoAPI, is also present in several Microsoft products for Macintosh. The vulnerability could enable an attacker who had a valid end-entity certificate to issue a subordinate certificate that, although bogus, would nevertheless pass validation. Because CryptoAPI is used by a wide range of applications, this could enable a variety of identity spoofing attacks.

Write Comment
Return to News

  Displaying 776 through 777 of 777
Prev | First
  The time now is 3:32:25 AM ET.
Any comment problems? E-mail us
#776 By 4240821 (188.253.25.226) at 1/18/2026 7:27:53 PM
https://telegra.ph/Handball-Em-The-Thrilling-New-Sport-Taking-the-World-by-Storm-01-17-3
https://telegra.ph/Apple-iPhone-Attacks-A-Deep-Dive-into-Vulnerabilities-and-Defenses-01-17
https://telegra.ph/Sander-Sagosen-Dominates-A-Masterclass-in-Handball-Brilliance-01-17
https://telegra.ph/Tanzanias-Kilimanjaro-Crowned-Worlds-Most-Enchanting-Summit-01-17
https://telegra.ph/NEC-Nijmegen-Stuns-Rivals-with-Late-Game-Heroics-01-17
https://telegra.ph/Bergendahl-Handboll-Unveiling-the-Future-of-the-Game-01-17
https://telegra.ph/Galatasarays-Electric-Comeback-Lions-Roar-Back-to-Secure-Dramatic-Victory-01-17-2
https://telegra.ph/Tamerlan-Dulhatov-The-Maverick-Mind-Reshaping-the-Future-of-Tech-01-17
https://telegra.ph/Trumps-Greenland-Gambit-Whats-the-Real-Reason-Behind-the-Bizarre-Land-Grab-01-17
https://telegra.ph/Broncos-vs-Bills-Mile-High-Mayhem-or-Buffalo-Blitz-01-17

#777 By 4240821 (188.253.25.226) at 1/22/2026 6:17:46 PM
https://telegra.ph/Medugnos-Mysterious-Meteorite-Makes-Man-a-Millionaire-Overnight-01-20
https://telegra.ph/Tyskland-Spanien-Håndbold-Knusende-Sejr-for-Tyskland-i-Dramatisk-Op-Gør-01-20
https://telegra.ph/Valentino-Garavanis-Unveiling-A-Symphony-of-Style-01-20
https://telegra.ph/Noorderlicht-B-België-Dazzling-Aurora-Lights-Up-Belgian-Skies-01-20
https://telegra.ph/Katie-Prices-Daring-New-Look-Sends-Fans-Wild-Is-This-Her-Boldest-Transformation-Yet-01-20-2
https://telegra.ph/Esperanza-Aguirre-A-Political-Dynamos-Enduring-Legacy-01-20-2
https://telegra.ph/DAZN-Drops-Bombshell-Mega-Fight-Announced-Fans-Go-Wild-01-20-2
https://telegra.ph/Tommy-Lee-Jones-Channels-Inner-Maverick-for-Unforeseen-Hollywood-Comeback-01-20
https://telegra.ph/Knight-of-the-Seven-Kingdoms-Faces-Dragons-in-Fiery-Showdown-01-20
https://telegra.ph/TÃ¥golyckan-A-Nation-Holds-Its-Breath-01-20-2

Write Comment
Return to News
  Displaying 776 through 777 of 777
Prev | First
  The time now is 3:32:25 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *