Security Advisories (5)
The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed message, via a brute-force attack.
- https://rt.cpan.org/Public/Bug/Display.html?id=71421
- https://bugzilla.redhat.com/show_bug.cgi?id=743567
- http://www.openwall.com/lists/oss-security/2011/10/05/9
- http://www.openwall.com/lists/oss-security/2011/10/05/5
- http://secunia.com/advisories/46275
- http://www.securityfocus.com/bid/49928
- http://osvdb.org/76025
Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified.
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same object reuses it, producing an identical "r". Keys used to sign more than once with an affected version should be considered compromised.
Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery. "Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prime search. The signing nonce and the private key are drawn from makerandom. Because the high bit is always set, the result is not uniform: its top bit is fixed, producing insecure values." An attacker who collects a modest number of signatures under an affected key, together with the public key, can recover the private key with a lattice attack. Keys used to sign with an affected version should be considered compromised and new keys should be generated.
NAME
Crypt::DSA::Signature - DSA signature object
SYNOPSIS
use Crypt::DSA::Signature;
my $sig = Crypt::DSA::Signature->new;
$sig->r($r);
$sig->s($s);
DESCRIPTION
AUTHOR & COPYRIGHTS
Please see the Crypt::DSA manpage for author, copyright, and license information.
Module Install Instructions
To install Crypt::DSA, copy and paste the appropriate command in to your terminal.
cpanm Crypt::DSA
perl -MCPAN -e shell
install Crypt::DSA
For more information on module installation, please visit the detailed CPAN module installation guide.