Featured Research

from universities, journals, and other organizations

Critical vulnerabilities in TLS implementation for Java

Date:
April 24, 2014
Source:
Ruhr-Universitaet-Bochum
Summary:
In January and April 2014, Oracle has released critical Java software security updates. They resolve vulnerabilities that affected the "Java Secure Socket Extension" (JSSE), a software library implementing the "Transport Layer Security" protocol (TLS). TLS is used to encrypt sensitive information transferred between browsers and web servers, such as passwords and credit card data, for example.

In January and April 2014, Oracle has released critical Java software security updates. They resolve, amongst others, three vulnerabilities discovered by researchers from the Horst G๖rtz Institute for IT Security at the Ruhr-Universitไt Bochum. These vulnerabilities affect the "Java Secure Socket Extension" (JSSE), a software library implementing the "Transport Layer Security" protocol (TLS). TLS is used to encrypt sensitive information transferred between browsers and web servers, such as passwords and credit card data, for example.

Related Articles


Similar to Heartbleed

Recently, the Heartbleed vulnerability of OpenSSL, the most important TLS implementation, has hit the headlines. Like OpenSSL, JSSE is an open source TLS implementation, maintained by Oracle. The researchers discovered three weaknesses in the JSSE library, two of which could be used to completely break the security of TLS encryption. Following the "responsible disclosure" paradigm, the team of Prof Dr J๖rg Schwenk privately informed Oracle about these vulnerabilities prior to public announcement. The researchers recommend to install Oracle's software updates for applications using JSSE as soon as possible.

How to break TLS in JSSE

JSSE was found vulnerable to so-called "Bleichenbacher attacks." First, the researchers intercepted an encrypted communication between a client (e.g. a web browser) and a server. Then, they sent a few thousands requests to the server; by examining the responses of the server they could compute the secret session key. This session key can be used to decrypt all data exchanged between client and server. The first vulnerability was based on critical information that the TLS server transmitted via error messages. The second one was based on different response times of the JSSE server. Bleichenbacher attacks are complex cryptographic attacks, also referred to as adaptive chosen-ciphertext attacks.

April patch from Oracle solves another problem

The April patch provided by Oracle also fixes another cryptographic algorithm (PKCS#1 v2.1, aka RSA-OAEP), which was vulnerable to a different adaptive chosen-ciphertext attack. This algorithm is not used in TLS, but in other security-critical applications, such as Web Services, for instance.


Story Source:

The above story is based on materials provided by Ruhr-Universitaet-Bochum. Note: Materials may be edited for content and length.


Cite This Page:

Ruhr-Universitaet-Bochum. "Critical vulnerabilities in TLS implementation for Java." ScienceDaily. ScienceDaily, 24 April 2014. <www.sciencedaily.com/releases/2014/04/140424102305.htm>.
Ruhr-Universitaet-Bochum. (2014, April 24). Critical vulnerabilities in TLS implementation for Java. ScienceDaily. Retrieved April 1, 2015 from www.sciencedaily.com/releases/2014/04/140424102305.htm
Ruhr-Universitaet-Bochum. "Critical vulnerabilities in TLS implementation for Java." ScienceDaily. www.sciencedaily.com/releases/2014/04/140424102305.htm (accessed April 1, 2015).

Share This


More From ScienceDaily



More Computers & Math News

Wednesday, April 1, 2015

Featured Research

from universities, journals, and other organizations


Featured Videos

from AP, Reuters, AFP, and other news services

Voice-Controlled GPS Helmet to Help Bikers

Voice-Controlled GPS Helmet to Help Bikers

Reuters - Innovations Video Online (Apr. 1, 2015) — Motorcyclists will no longer have to rely on maps or GPS systems, both of which require riders to take their eyes off the road, once a new Russian smart helmet goes on sale this summer. Jim Drury reports. Video provided by Reuters
Powered by NewsLook.com
7-Year-Old Girl Gets 3-D Printed 'robohand'

7-Year-Old Girl Gets 3-D Printed 'robohand'

AP (Mar. 31, 2015) — Although she never had much interest in prosthetic limbs before, Faith Lennox couldn&apos;t wait to slip on her new robohand. The 7-year-old, who lost part of her left arm when she was a baby, grabbed it as soon as it came off a 3-D printer. (March 31) Video provided by AP
Powered by NewsLook.com
Dash Button Shows Amazon Is Going After Grocers

Dash Button Shows Amazon Is Going After Grocers

Newsy (Mar. 31, 2015) — Dash Button enables you to order regular household items with the push of a button, yet another play by Amazon to grab everyday customers. Video provided by Newsy
Powered by NewsLook.com
What The Charter, Bright House Deal Means For Cable

What The Charter, Bright House Deal Means For Cable

Newsy (Mar. 31, 2015) — Tuesday, Charter announced the two companies had come to a "definitive agreement," with Charter paying $10.4 billion for Bright House. Video provided by Newsy
Powered by NewsLook.com

Search ScienceDaily

Number of stories in archives: 140,361

Find with keyword(s):
 
Enter a keyword or phrase to search ScienceDaily for related topics and research stories.

Save/Print:
Share:  

Breaking News:

Strange & Offbeat Stories

 

Space & Time

Matter & Energy

Computers & Math

In Other News

... from NewsDaily.com

Science News

Health News

Environment News

Technology News



Save/Print:
Share:  

Free Subscriptions


Get the latest science news with ScienceDaily's free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Get Social & Mobile


Keep up to date with the latest news from ScienceDaily via social networks and mobile apps:

Have Feedback?


Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
Mobile iPhone Android Web
Follow Facebook Twitter Google+
Subscribe RSS Feeds Email Newsletters
Latest Headlines Health & Medicine Mind & Brain Space & Time Matter & Energy Computers & Math Plants & Animals Earth & Climate Fossils & Ruins