PT-2009-2753 · Openssl · Openssl
Published
2009-01-07
·
Updated
2018-10-11
·
CVE-2009-0047
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gale versions 0.99 and earlier
Description
The issue arises from improper checking of the return value from the OpenSSL EVP VerifyFinal function. This allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
Recommendations
For versions 0.99 and earlier, ensure proper validation of the certificate chain by correctly checking the return value from the OpenSSL EVP VerifyFinal function. As a temporary workaround, consider restricting the use of DSA and ECDSA keys until a proper fix is implemented.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl