CVE-2008-5077
published 2009-01-07CVE-2008-5077: OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of…
PriorityP341medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
5.15%
91.5th percentile
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
Affected
174 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arrl | tqsllib | — | — |
| berkeley | boinc_client | — | — |
| berkeley | boinc_client | — | — |
| berkeley | boinc_client | >= 0 < 6.2.14-3 | 6.2.14-3 |
| berkeley | boinc_client | >= 0 < 6.2.14-3 | 6.2.14-3 |
| berkeley | boinc_client | >= 0 < 6.2.14-3 | 6.2.14-3 |
| berkeley | boinc_client | >= 0 < 6.2.14-3 | 6.2.14-3 |
| debian | bind9 | < bind9 1:9.5.1.dfsg.P1-1 (bookworm) | bind9 1:9.5.1.dfsg.P1-1 (bookworm) |
| debian | bind9 | — | — |
| debian | boinc | < boinc 6.2.14-3 (bookworm) | boinc 6.2.14-3 (bookworm) |
| debian | erlang | — | — |
| debian | evolution-data-server | < evolution-data-server 2.24.5-2 (bookworm) | evolution-data-server 2.24.5-2 (bookworm) |
| debian | lasso | < lasso 2.2.1-2 (bookworm) | lasso 2.2.1-2 (bookworm) |
| debian | libcrypt-openssl-dsa-perl | < libcrypt-openssl-dsa-perl 0.13-4 (bookworm) | libcrypt-openssl-dsa-perl 0.13-4 (bookworm) |
| debian | m2crypto | — | — |
| debian | ntp | < ntp 1:4.2.4p4+dfsg-8 (bullseye) | ntp 1:4.2.4p4+dfsg-8 (bullseye) |
| debian | openssl | < openssl 0.9.8g-15 (bookworm) | openssl 0.9.8g-15 (bookworm) |
| eid | eidlib | <= 2.6.0 | — |
| entrouvert | lasso | <= 2.2.1-0 | — |
| entrouvert | lasso | — | — |
| entrouvert | lasso | — | — |
| entrouvert | lasso | >= 0 < 2.2.1-2 | 2.2.1-2 |
| entrouvert | lasso | >= 0 < 2.2.1-2 | 2.2.1-2 |
| entrouvert | lasso | >= 0 < 2.2.1-2 | 2.2.1-2 |
| entrouvert | lasso | >= 0 < 2.2.1-2 | 2.2.1-2 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
m2crypto: OpenSSL incorrect checks for malformed signatures
vendor_redhat·2009-01-11·CVSS 5.8
CVE-2009-0127 [MEDIUM] m2crypto: OpenSSL incorrect checks for malformed signatures
m2crypto: OpenSSL incorrect checks for malformed signatures
M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto.
Statement: Red Hat does not consider this to be a security issue. M2Crypto provides python interfaces to multiple OpenSSL functions. Neither of those interfaces is further used by M2Crypto in an insecure way. Additionally, no application shipped in Red Hat Enterprise Linux is know
Red Hat
libnasl: OpenSSL incorrect checks for malformed signatures
vendor_redhat·2009-01-11·CVSS 5.8
CVE-2009-0125 [MEDIUM] libnasl: OpenSSL incorrect checks for malformed signatures
libnasl: OpenSSL incorrect checks for malformed signatures
NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification.
Red Hat
boinc-client: Does not check the RSA_public_decrypt() return value.
vendor_redhat·2009-01-11·CVSS 5.8
CVE-2009-0126 [MEDIUM] boinc-client: Does not check the RSA_public_decrypt() return value.
boinc-client: Does not check the RSA_public_decrypt() return value.
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Red Hat
perl-Crypt-OpenSSL-DSA: do_verify() doesn't fail on errors in OpenSSL DSA_do_verify()
vendor_redhat·2009-01-11·CVSS 5.8
CVE-2009-0129 [MEDIUM] perl-Crypt-OpenSSL-DSA: do_verify() doesn't fail on errors in OpenSSL DSA_do_verify()
perl-Crypt-OpenSSL-DSA: do_verify() doesn't fail on errors in OpenSSL DSA_do_verify()
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Red Hat
tqsllib: OpenSSL incorrect checks for malformed signatures
vendor_redhat·2009-01-11·CVSS 5.8
CVE-2009-0124 [MEDIUM] tqsllib: OpenSSL incorrect checks for malformed signatures
tqsllib: OpenSSL incorrect checks for malformed signatures
The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Red Hat
ntp incorrectly checks for malformed signatures
vendor_redhat·2009-01-07·CVSS 5.8
CVE-2009-0021 [MEDIUM] ntp incorrectly checks for malformed signatures
ntp incorrectly checks for malformed signatures
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2009-01-07
CVE-2008-5077 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL vulnerability
It was discovered that OpenSSL did not properly perform signature verification
on DSA and ECDSA keys. If user or automated system connected to a malicious
server or a remote attacker were able to perform a machine-in-the-middle attack,
this flaw could be exploited to view sensitive information.
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
BSD
FreeBSD-SA-09:02.openssl: OpenSSL incorrectly checks for malformed signatures
bsd_advisories·2009-01-07·CVSS 5.8
CVE-2008-5077 [MEDIUM] FreeBSD-SA-09:02.openssl: OpenSSL incorrectly checks for malformed signatures
FreeBSD-SA-09:02.openssl Security Advisory
The FreeBSD Project
Topic: OpenSSL incorrectly checks for malformed signatures
Category: contrib
Module: openssl
Announced: 2009-01-07
Credits: Google Security Team
Affects: All FreeBSD releases
Corrected: 2009-01-07 21:03:41 UTC (RELENG_7, 7.1-STABLE)
2009-01-07 20:17:55 UTC (RELENG_7_1, 7.1-RELEASE-p1)
2009-01-07 20:17:55 UTC (RELENG_7_0, 7.0-RELEASE-p8)
2009-01-07 20:17:55 UTC (RELENG_6, 6.4-STABLE)
2009-01-07 20:17:55 UTC (RELENG_6_4, 6.4-RELEASE-p2)
2009-01-07 20:17:55 UTC (RELENG_6_3, 6.3-RELEASE-p8)
CVE Name: CVE-2008-5077
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
FreeBSD includes software from th
Red Hat
OpenSSL Incorrect checks for malformed signatures
vendor_redhat·2009-01-07·CVSS 5.8
CVE-2008-5077 [MEDIUM] OpenSSL Incorrect checks for malformed signatures
OpenSSL Incorrect checks for malformed signatures
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
Red Hat
bind: DSA_do_verify() returns check issue
vendor_redhat·2009-01-07·CVSS 5.8
CVE-2009-0025 [MEDIUM] bind: DSA_do_verify() returns check issue
bind: DSA_do_verify() returns check issue
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Debian
CVE-2009-0547: evolution-data-server - Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text wi...
vendor_debian·2009·CVSS 5.8
CVE-2009-0547 [MEDIUM] CVE-2009-0547: evolution-data-server - Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text wi...
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
Scope: local
bookworm: resolved (fixed in 2.24.5-2)
bullseye: resolved (fixed in 2.24.5-2)
forky: resolved (fixed in 2.24.5-2)
sid: resolved (fixed in 2.24.5-2)
trixie: resolved (fixed in 2.24.5-2)
Debian
CVE-2009-0126: boinc - The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infr...
vendor_debian·2009·CVSS 5.8
CVE-2009-0126 [MEDIUM] CVE-2009-0126: boinc - The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infr...
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scope: local
bookworm: resolved (fixed in 6.2.14-3)
bullseye: resolved (fixed in 6.2.14-3)
forky: resolved (fixed in 6.2.14-3)
sid: resolved (fixed in 6.2.14-3)
trixie: resolved (fixed in 6.2.14-3)
Debian
CVE-2009-0021: ntp - NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the ...
vendor_debian·2009·CVSS 5.8
CVE-2009-0021 [MEDIUM] CVE-2009-0021: ntp - NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the ...
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Scope: local
bullseye: resolved (fixed in 1:4.2.4p4+dfsg-8)
Debian
CVE-2009-0129: libcrypt-openssl-dsa-perl - libcrypt-openssl-dsa-perl does not properly check the return value from the Open...
vendor_debian·2009·CVSS 5.8
CVE-2009-0129 [MEDIUM] CVE-2009-0129: libcrypt-openssl-dsa-perl - libcrypt-openssl-dsa-perl does not properly check the return value from the Open...
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scope: local
bookworm: resolved (fixed in 0.13-4)
bullseye: resolved (fixed in 0.13-4)
forky: resolved (fixed in 0.13-4)
sid: resolved (fixed in 0.13-4)
trixie: resolved (fixed in 0.13-4)
Debian
CVE-2009-0127: m2crypto - M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFin...
vendor_debian·2009·CVSS 5.8
CVE-2009-0127 [MEDIUM] CVE-2009-0127: m2crypto - M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFin...
M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto.
Scope: local
bookworm: open
bullseye: open
trixie: open
Debian
CVE-2009-0265: bind9 - Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check...
vendor_debian·2009·CVSS 5.8
CVE-2009-0265 [MEDIUM] CVE-2009-0265: bind9 - Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check...
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2009-0050: lasso - Lasso 2.2.1 and earlier does not properly check the return value from the OpenSS...
vendor_debian·2009·CVSS 5.8
CVE-2009-0050 [MEDIUM] CVE-2009-0050: lasso - Lasso 2.2.1 and earlier does not properly check the return value from the OpenSS...
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scope: local
bookworm: resolved (fixed in 2.2.1-2)
bullseye: resolved (fixed in 2.2.1-2)
forky: resolved (fixed in 2.2.1-2)
sid: resolved (fixed in 2.2.1-2)
trixie: resolved (fixed in 2.2.1-2)
Debian
CVE-2009-0130: erlang - lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value...
vendor_debian·2009·CVSS 5.8
CVE-2009-0130 [MEDIUM] CVE-2009-0130: erlang - lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value...
lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Debian
CVE-2009-0025: bind9 - BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return ...
vendor_debian·2009·CVSS 5.8
CVE-2009-0025 [MEDIUM] CVE-2009-0025: bind9 - BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return ...
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scope: local
bookworm: resolved (fixed in 1:9.5.1.dfsg.P1-1)
bullseye: resolved (fixed in 1:9.5.1.dfsg.P1-1)
forky: resolved (fixed in 1:9.5.1.dfsg.P1-1)
sid: resolved (fixed in 1:9.5.1.dfsg.P1-1)
trixie: resolved (fixed in 1:9.5.1.dfsg.P1-1)
Red Hat
evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)
vendor_redhat·2008-12-11·CVSS 5.8
CVE-2009-0547 [MEDIUM] evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)
evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
Debian
CVE-2008-5077: openssl - OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP...
vendor_debian·2008·CVSS 5.8
CVE-2008-5077 [MEDIUM] CVE-2008-5077: openssl - OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP...
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
Scope: local
bookworm: resolved (fixed in 0.9.8g-15)
bullseye: resolved (fixed in 0.9.8g-15)
forky: resolved (fixed in 0.9.8g-15)
sid: resolved (fixed in 0.9.8g-15)
trixie: resolved (fixed in 0.9.8g-15)
Red Hat
CVE-2009-0265: Internet Systems Consortium (ISC) BIND 9
vendor_redhat·CVSS 5.8
CVE-2009-0265 [MEDIUM] CVE-2009-0265: Internet Systems Consortium (ISC) BIND 9
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Statement: Not vulnerable. This issue did not affect the versions of BIND as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
GHSA
GHSA-5fwv-px3v-6qxv: OpenSSL 0
ghsa_unreviewed·2022-05-14
CVE-2008-5077 [MEDIUM] CWE-20 GHSA-5fwv-px3v-6qxv: OpenSSL 0
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
GHSA
GHSA-7ccf-7vx8-76vm: Lasso 2
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0050 [MEDIUM] CWE-20 GHSA-7ccf-7vx8-76vm: Lasso 2
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-cvwp-gwp2-6xqh: libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote a
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0129 [MEDIUM] CWE-287 GHSA-cvwp-gwp2-6xqh: libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote a
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-hcwf-6ghh-6m6f: BIND 9
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0025 [MEDIUM] CWE-287 GHSA-hcwf-6ghh-6m6f: BIND 9
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-4q4m-qx69-vcgq: NTP 4
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0021 [MEDIUM] CWE-287 GHSA-4q4m-qx69-vcgq: NTP 4
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-38p9-hv7m-9vv5: ** DISPUTED ** NOTE: this issue has been disputed by the upstream vendor
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0125 [MEDIUM] CWE-287 GHSA-38p9-hv7m-9vv5: ** DISPUTED ** NOTE: this issue has been disputed by the upstream vendor
** DISPUTED ** NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification."
GHSA
GHSA-969m-2vwf-hmrr: plugins/crypto/openssl/crypto_openssl
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0128 [MEDIUM] CWE-287 GHSA-969m-2vwf-hmrr: plugins/crypto/openssl/crypto_openssl
plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-gq89-cf9v-xh3g: Evolution 2
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0547 [MEDIUM] GHSA-gq89-cf9v-xh3g: Evolution 2
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
GHSA
GHSA-2q3r-gf9c-fhv3: The tqsl_verifyDataBlock function in openssl_cert
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0124 [MEDIUM] CWE-287 GHSA-2q3r-gf9c-fhv3: The tqsl_verifyDataBlock function in openssl_cert
The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-7r33-3gh8-245q: Gale 0
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0047 [MEDIUM] CWE-287 GHSA-7r33-3gh8-245q: Gale 0
Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-9wmh-wp74-54qv: Sun GridEngine 5
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0046 [MEDIUM] CWE-287 GHSA-9wmh-wp74-54qv: Sun GridEngine 5
Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-wc42-38jg-6fv2: OpenEvidence 1
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0048 [MEDIUM] CWE-287 GHSA-wc42-38jg-6fv2: OpenEvidence 1
OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-74cx-pw34-jqwr: ** DISPUTED ** lib/crypto/c_src/crypto_drv
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0130 [MEDIUM] CWE-287 GHSA-74cx-pw34-jqwr: ** DISPUTED ** lib/crypto/c_src/crypto_drv
** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid."
GHSA
GHSA-7wm2-j7jq-4xvr: ZXID 0
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0051 [MEDIUM] CWE-287 GHSA-7wm2-j7jq-4xvr: ZXID 0
ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-gpcp-59gr-fj3v: The decrypt_public function in lib/crypt
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0126 [MEDIUM] CWE-287 GHSA-gpcp-59gr-fj3v: The decrypt_public function in lib/crypt
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-mrwj-9mpp-w94q: Internet Systems Consortium (ISC) BIND 9
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0265 [MEDIUM] CWE-252 GHSA-mrwj-9mpp-w94q: Internet Systems Consortium (ISC) BIND 9
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
GHSA
GHSA-j42w-rpgw-49cw: Belgian eID middleware (eidlib) 2
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0049 [MEDIUM] CWE-287 GHSA-j42w-rpgw-49cw: Belgian eID middleware (eidlib) 2
Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-933f-4fwg-646j: ** DISPUTED ** M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0127 [MEDIUM] CWE-287 GHSA-933f-4fwg-646j: ** DISPUTED ** M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_
** DISPUTED ** M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto."
OSV
CVE-2009-0547: Evolution 2
osv·2009-02-12·CVSS 5.8
CVE-2009-0547 [MEDIUM] CVE-2009-0547: Evolution 2
Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077.
OSV
CVE-2009-0129: libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote a
osv·2009-01-15·CVSS 5.8
CVE-2009-0129 [MEDIUM] CVE-2009-0129: libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote a
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
OSV
CVE-2009-0126: The decrypt_public function in lib/crypt
osv·2009-01-15·CVSS 5.8
CVE-2009-0126 [MEDIUM] CVE-2009-0126: The decrypt_public function in lib/crypt
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
OSV
CVE-2009-0130: lib/crypto/c_src/crypto_drv
osv·2009-01-15·CVSS 5.8
CVE-2009-0130 [MEDIUM] CVE-2009-0130: lib/crypto/c_src/crypto_drv
lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid.
OSV
CVE-2009-0127: M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify funct
osv·2009-01-15·CVSS 5.8
CVE-2009-0127 [MEDIUM] CVE-2009-0127: M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify funct
M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto.
OSV
CVE-2009-0021: NTP 4
osv·2009-01-07·CVSS 5.8
CVE-2009-0021 [MEDIUM] CVE-2009-0021: NTP 4
NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
OSV
CVE-2009-0025: BIND 9
osv·2009-01-07·CVSS 5.8
CVE-2009-0025 [MEDIUM] CVE-2009-0025: BIND 9
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
OSV
CVE-2008-5077: OpenSSL 0
osv·2009-01-07·CVSS 5.8
CVE-2008-5077 [MEDIUM] CVE-2008-5077: OpenSSL 0
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
OSV
CVE-2009-0050: Lasso 2
osv·2009-01-07·CVSS 5.8
CVE-2009-0050 [MEDIUM] CVE-2009-0050: Lasso 2
Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0129 perl-Crypt-OpenSSL-DSA: do_verify() doesn't fail on errors in OpenSSL DSA_do_verify()
bugzilla·2009-02-17·CVSS 5.8
CVE-2009-0129 [MEDIUM] CVE-2009-0129 perl-Crypt-OpenSSL-DSA: do_verify() doesn't fail on errors in OpenSSL DSA_do_verify()
CVE-2009-0129 perl-Crypt-OpenSSL-DSA: do_verify() doesn't fail on errors in OpenSSL DSA_do_verify()
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511519
http://openwall.com/lists/oss-security/2009/01/12/4
http://sourceforge.net/tracker/index.php?func=detail&aid=2545158&group_id=73194&atid=537053
The last is the upstream bug report with an attached patch to fix the issue.
Discussion:
Created attachment 332302
patch from Debian's update to fix the issue
---
perl-Crypt-OpenSSL-DSA-0.13-12.fc10
Bugzilla
CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)
bugzilla·2009-02-10·CVSS 5.0
CVE-2009-0547 [MEDIUM] CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)
CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)
A man-in-the-middle-attack possibility was found in the way evolution
handles the Secure / Multipurpose Internet Mail Extensions (S/MIME) mail messages. If the S/MIME email was sign, the email message subsequently
modified, evolution would consider the S/MIME message signature to be valid
even for such a modified message. An attacker could use this flaw to
modify the emails (message integrity violation) between communicating part.
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508479
Discussion:
This issue does NOT affect the version of the evolution package,
as shipped with Red Hat Enteprise Linux 3.
This issue affects the versions of the evolution package
Bugzilla
CVE-2009-0126 boinc-client: Does not check the RSA_public_decrypt() return value.
bugzilla·2009-01-12·CVSS 5.8
CVE-2009-0126 [MEDIUM] CVE-2009-0126 boinc-client: Does not check the RSA_public_decrypt() return value.
CVE-2009-0126 boinc-client: Does not check the RSA_public_decrypt() return value.
The Berkeley Open Infrastructure for Network Computing (BOINC) client software
incorrectly checked the result after calling the RSA_public_decrypt function,
allowing a malformed signature to be treated as a good signature rather
than as an error. This issue affected the signature checks on RSA keys used
with SSL/TLS.
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521
This issue is related with recent OpenSSL's CVE-2008-5077 flaw.
Discussion:
This issue affects all versions of the boinc-client package, as shipped
with Fedora updates of 9, 10 and devel.
Please fix.
Relevant part of the code (lib/crypt.C):
228 int decrypt_public(R_RSA_PUBLIC_KEY& key, DATA_BLOCK& in, DATA_BLOCK& out) {
2
Bugzilla
CVE-2009-0125 libnasl: OpenSSL incorrect checks for malformed signatures
bugzilla·2009-01-12·CVSS 5.8
CVE-2009-0125 [MEDIUM] CVE-2009-0125 libnasl: OpenSSL incorrect checks for malformed signatures
CVE-2009-0125 libnasl: OpenSSL incorrect checks for malformed signatures
The library routines package for NASL (the scripting language designed for the Nessus security scanner) incorrectly checked the result after
calling the DSA_do_verify function, allowing a malformed signature
to be treated as a good signature rather than as an error. This issue
affected the signature checks on DSA keys used with SSL/TLS.
Relevant part of the code (nasl/nasl_crypto2.c):
647 if (DSA_do_verify((unsigned char*)data, datalen, sig, dsa))
648 retc->x.i_val = 1;
Proposed patch:
- if (DSA_do_verify((unsigned char*)data, datalen, sig, dsa))
+ if (DSA_do_verify((unsigned char*)data, datalen, sig, dsa) == 1)
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511517
This issue is related with recent
Bugzilla
CVE-2009-0127 m2crypto: OpenSSL incorrect checks for malformed signatures
bugzilla·2009-01-12·CVSS 5.8
CVE-2009-0127 [MEDIUM] CVE-2009-0127 m2crypto: OpenSSL incorrect checks for malformed signatures
CVE-2009-0127 m2crypto: OpenSSL incorrect checks for malformed signatures
The m2crypto package (allowing to call OpenSSL functions from python scripts)
incorrectly checked the result after calling various cryptographic decryption functions, allowing a malformed signature to be treated as a good signature rather than as an error. This issue affected the signature checks on DSA keys
and ECDSA keys used with SSL/TLS.
There are also calls to DSA_verify(), ECDSA_verify(), DSA_do_verify()
and ECDSA_do_verify() that seem to think that -1 means error,
and then return the return code. But 0 is also an error case (see
man DSA_do_verify for example).
Relevant part of the code: (SWIG/_dsa.i):
261 ret = DSA_do_verify(vbuf, vlen, sig, dsa);
262 DSA_SIG_free(sig);
263 if (ret == -1)
264 PyErr_SetStrin
Bugzilla
CVE-2009-0124 tqsllib: OpenSSL incorrect checks for malformed signatures
bugzilla·2009-01-12·CVSS 5.8
CVE-2009-0124 [MEDIUM] CVE-2009-0124 tqsllib: OpenSSL incorrect checks for malformed signatures
CVE-2009-0124 tqsllib: OpenSSL incorrect checks for malformed signatures
The TrustedQSL library incorrectly checked the result after
calling the EVP_VerifyFinal function, allowing a malformed signature
to be treated as a good signature rather than as an error.
Proposed patch:
- if (!EVP_VerifyFinal(&ctx, sig, slen, TQSL_API_TO_CERT(cert)->key)) {
+ if (EVP_VerifyFinal(&ctx, sig, slen, TQSL_API_TO_CERT(cert)->key) <= 0) {
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511509
Discussion:
This issue is related with recent OpenSSL's CVE-2008-5077 flaw.
This issue affects all versions of the tqsllib package, as shipped
with Fedora releases of 9, 10 and devel.
Please fix.
---
tqsllib-2.0-5.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/u
Bugzilla
CVE-2009-0025 bind: DSA_do_verify() returns check issue
bugzilla·2009-01-06·CVSS 5.8
CVE-2009-0025 [MEDIUM] CVE-2009-0025 bind: DSA_do_verify() returns check issue
CVE-2009-0025 bind: DSA_do_verify() returns check issue
Gave CVE-2009-0025 to ISC for their advisory.
Discussion:
Now public, removing embargo:
https://www.isc.org/node/373
---
nternet Systems Consortium Security Advisory.
BIND: EVP_VerifyFinal() and DSA_do_verify() return checks.
7 January 2009
Versions affected:
BIND 9.0 (all versions)
BIND 9.1 (all versions)
BIND 9.2 (all versions)
BIND 9.3.0, 9.3.1, 9.3.2, 9.3.3, 9.3.4, 9.3.5, 9.3.6
BIND 9.4.0, 9.4.1, 9.4.2, 9.4.3
BIND 9.5.0, 9.5.1
BIND 9.6.0
Severity: Low.
Description:
Return values from OpenSSL library functions EVP_VerifyFinal()
and DSA_do_verify() were not checked properly.
Impact:
It is theoretically possible to spoof answers returned from
zones using the DNSKEY algorithms DSA (3) and NSEC3DSA (6).
Workaround:
BIND 9
Bugzilla
CVE-2009-0021 ntp incorrectly checks for malformed signatures
bugzilla·2008-12-17·CVSS 5.8
CVE-2009-0021 [MEDIUM] CVE-2009-0021 ntp incorrectly checks for malformed signatures
CVE-2009-0021 ntp incorrectly checks for malformed signatures
Embargoed until Jan 7th 2009.
Incorrect checks for malformed signatures
Several functions inside NTP incorrectly checked the result after calling the OpenSSL EVP_VerifyFinal function, allowing a malformed signature to be treated as a good signature rather than as an error.
A remote attacker who is in control of a malicious server or who can use a 'man in the middle' attack could present a malformed signature from a certificate chain to a vulnerable client, bypassing validation. This issue would only affect non-default installations that are set up to use cryptography to authenticate clients and servers to each other.
This vulnerability is tracked as CVE-2009-0021 and is similar to
CVE-2008-5077 which affects OpenSSL itself.
Bugzilla
CVE-2008-5077 OpenSSL Incorrect checks for malformed signatures
bugzilla·2008-12-16·CVSS 5.8
CVE-2008-5077 [MEDIUM] CVE-2008-5077 OpenSSL Incorrect checks for malformed signatures
CVE-2008-5077 OpenSSL Incorrect checks for malformed signatures
Draft advisory from OpenSSL team:
OpenSSL Security Advisory [07-Jan-2009]
Incorrect checks for malformed signatures
Several functions inside OpenSSL incorrectly checked the result after
calling the EVP_VerifyFinal function, allowing a malformed signature
to be treated as a good signature rather than as an error. This issue
affected the signature checks on DSA and ECDSA keys used with
SSL/TLS.
One way to exploit this flaw would be for a remote attacker who is in
control of a malicious server or who can use a 'man in the middle'
attack to present a malformed SSL/TLS signature from a certificate chain
to a vulnerable client, bypassing validation.
This vulnerability is tracked as CVE-2008-5077.
The OpenSSL security team wou
http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.htmlhttp://marc.info/?l=bugtraq&m=123859864430555&w=2http://marc.info/?l=bugtraq&m=124277349419254&w=2http://marc.info/?l=bugtraq&m=127678688104458&w=2http://secunia.com/advisories/33338http://secunia.com/advisories/33394http://secunia.com/advisories/33436http://secunia.com/advisories/33557http://secunia.com/advisories/33673http://secunia.com/advisories/33765http://secunia.com/advisories/34211http://secunia.com/advisories/35074http://secunia.com/advisories/35108http://secunia.com/advisories/39005http://security.gentoo.org/glsa/glsa-200902-02.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.544796http://sunsolve.sun.com/search/document.do?assetkey=1-66-250826-1http://support.apple.com/kb/HT3549http://support.avaya.com/elmodocs2/security/ASA-2009-038.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=837653http://voodoo-circle.sourceforge.net/sa/sa-20090123-01.htmlhttp://www.ocert.org/advisories/ocert-2008-016.htmlhttp://www.openssl.org/news/secadv_20090107.txthttp://www.redhat.com/support/errata/RHSA-2009-0004.htmlhttp://www.securityfocus.com/archive/1/499827/100/0/threadedhttp://www.securityfocus.com/archive/1/502322/100/0/threadedhttp://www.securityfocus.com/bid/33150http://www.securitytracker.com/id?1021523http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0004.htmlhttp://www.vupen.com/english/advisories/2009/0040http://www.vupen.com/english/advisories/2009/0289http://www.vupen.com/english/advisories/2009/0362http://www.vupen.com/english/advisories/2009/0558http://www.vupen.com/english/advisories/2009/0904http://www.vupen.com/english/advisories/2009/0913http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1338https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6380https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9155https://usn.ubuntu.com/704-1/http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.htmlhttp://marc.info/?l=bugtraq&m=123859864430555&w=2http://marc.info/?l=bugtraq&m=124277349419254&w=2http://marc.info/?l=bugtraq&m=127678688104458&w=2http://secunia.com/advisories/33338http://secunia.com/advisories/33394http://secunia.com/advisories/33436http://secunia.com/advisories/33557http://secunia.com/advisories/33673http://secunia.com/advisories/33765http://secunia.com/advisories/34211http://secunia.com/advisories/35074http://secunia.com/advisories/35108http://secunia.com/advisories/39005http://security.gentoo.org/glsa/glsa-200902-02.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.544796http://sunsolve.sun.com/search/document.do?assetkey=1-66-250826-1http://support.apple.com/kb/HT3549http://support.avaya.com/elmodocs2/security/ASA-2009-038.htmhttp://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=837653http://voodoo-circle.sourceforge.net/sa/sa-20090123-01.htmlhttp://www.ocert.org/advisories/ocert-2008-016.htmlhttp://www.openssl.org/news/secadv_20090107.txthttp://www.redhat.com/support/errata/RHSA-2009-0004.htmlhttp://www.securityfocus.com/archive/1/499827/100/0/threadedhttp://www.securityfocus.com/archive/1/502322/100/0/threadedhttp://www.securityfocus.com/bid/33150http://www.securitytracker.com/id?1021523http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0004.htmlhttp://www.vupen.com/english/advisories/2009/0040http://www.vupen.com/english/advisories/2009/0289http://www.vupen.com/english/advisories/2009/0362http://www.vupen.com/english/advisories/2009/0558http://www.vupen.com/english/advisories/2009/0904http://www.vupen.com/english/advisories/2009/0913http://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1338https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6380https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9155https://usn.ubuntu.com/704-1/
2009-01-07
Published