Featured Research

from universities, journals, and other organizations

Critical vulnerabilities in TLS implementation for Java

Date:
April 24, 2014
Source:
Ruhr-Universitaet-Bochum
Summary:
In January and April 2014, Oracle has released critical Java software security updates. They resolve vulnerabilities that affected the "Java Secure Socket Extension" (JSSE), a software library implementing the "Transport Layer Security" protocol (TLS). TLS is used to encrypt sensitive information transferred between browsers and web servers, such as passwords and credit card data, for example.

In January and April 2014, Oracle has released critical Java software security updates. They resolve, amongst others, three vulnerabilities discovered by researchers from the Horst G๖rtz Institute for IT Security at the Ruhr-Universitไt Bochum. These vulnerabilities affect the "Java Secure Socket Extension" (JSSE), a software library implementing the "Transport Layer Security" protocol (TLS). TLS is used to encrypt sensitive information transferred between browsers and web servers, such as passwords and credit card data, for example.

Similar to Heartbleed

Recently, the Heartbleed vulnerability of OpenSSL, the most important TLS implementation, has hit the headlines. Like OpenSSL, JSSE is an open source TLS implementation, maintained by Oracle. The researchers discovered three weaknesses in the JSSE library, two of which could be used to completely break the security of TLS encryption. Following the "responsible disclosure" paradigm, the team of Prof Dr J๖rg Schwenk privately informed Oracle about these vulnerabilities prior to public announcement. The researchers recommend to install Oracle's software updates for applications using JSSE as soon as possible.

How to break TLS in JSSE

JSSE was found vulnerable to so-called "Bleichenbacher attacks." First, the researchers intercepted an encrypted communication between a client (e.g. a web browser) and a server. Then, they sent a few thousands requests to the server; by examining the responses of the server they could compute the secret session key. This session key can be used to decrypt all data exchanged between client and server. The first vulnerability was based on critical information that the TLS server transmitted via error messages. The second one was based on different response times of the JSSE server. Bleichenbacher attacks are complex cryptographic attacks, also referred to as adaptive chosen-ciphertext attacks.

April patch from Oracle solves another problem

The April patch provided by Oracle also fixes another cryptographic algorithm (PKCS#1 v2.1, aka RSA-OAEP), which was vulnerable to a different adaptive chosen-ciphertext attack. This algorithm is not used in TLS, but in other security-critical applications, such as Web Services, for instance.


Story Source:

The above story is based on materials provided by Ruhr-Universitaet-Bochum. Note: Materials may be edited for content and length.


Cite This Page:

Ruhr-Universitaet-Bochum. "Critical vulnerabilities in TLS implementation for Java." ScienceDaily. ScienceDaily, 24 April 2014. <www.sciencedaily.com/releases/2014/04/140424102305.htm>.
Ruhr-Universitaet-Bochum. (2014, April 24). Critical vulnerabilities in TLS implementation for Java. ScienceDaily. Retrieved August 28, 2014 from www.sciencedaily.com/releases/2014/04/140424102305.htm
Ruhr-Universitaet-Bochum. "Critical vulnerabilities in TLS implementation for Java." ScienceDaily. www.sciencedaily.com/releases/2014/04/140424102305.htm (accessed August 28, 2014).

Share This




More Computers & Math News

Thursday, August 28, 2014

Featured Research

from universities, journals, and other organizations


Featured Videos

from AP, Reuters, AFP, and other news services

Hackerspace Provides Hackers Creative Haven

Hackerspace Provides Hackers Creative Haven

AP (Aug. 27, 2014) — HeatSync Labs, a so-called hackerspace in Mesa, Arizona provides members and the public alike a space to allow their creative juices to flow and make their tech dreams into a reality. (Aug 27) Video provided by AP
Powered by NewsLook.com
Why A 12.9-Inch iPad Would Make Sense For Apple

Why A 12.9-Inch iPad Would Make Sense For Apple

Newsy (Aug. 27, 2014) — There are two big knocks against the iPad — productivity limits and slumping sales. Here's how a bigger iPad could fix both of Apple's problems. Video provided by Newsy
Powered by NewsLook.com
Smartphone App Tracks Your Heart Rate

Smartphone App Tracks Your Heart Rate

Ivanhoe (Aug. 27, 2014) — A new app that can track your heart rate 24/7 is available for download in your app store and its convenience could save your life. Video provided by Ivanhoe
Powered by NewsLook.com
Nationwide Time Warner Internet Crash Results In More Bad PR

Nationwide Time Warner Internet Crash Results In More Bad PR

Newsy (Aug. 27, 2014) — The nationwide Internet crash resulted in millions of customers' internet connection to go out for hours. Video provided by Newsy
Powered by NewsLook.com

Search ScienceDaily

Number of stories in archives: 140,361

Find with keyword(s):
 
Enter a keyword or phrase to search ScienceDaily for related topics and research stories.

Save/Print:
Share:  

Breaking News:
from the past week

In Other News

... from NewsDaily.com

Science News

Health News

Environment News

Technology News



Save/Print:
Share:  

Free Subscriptions


Get the latest science news with ScienceDaily's free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Get Social & Mobile


Keep up to date with the latest news from ScienceDaily via social networks and mobile apps:

Have Feedback?


Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
Mobile iPhone Android Web
Follow Facebook Twitter Google+
Subscribe RSS Feeds Email Newsletters
Latest Headlines Health & Medicine Mind & Brain Space & Time Matter & Energy Computers & Math Plants & Animals Earth & Climate Fossils & Ruins