cbcvebase.
CVE-2008-5077
published 2009-01-07

CVE-2008-5077: OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of…

PriorityP341medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
5.15%
91.5th percentile
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

Affected

174 ranges· showing 25
VendorProductVersion rangeFixed in
arrltqsllib
berkeleyboinc_client
berkeleyboinc_client
berkeleyboinc_client>= 0 < 6.2.14-36.2.14-3
berkeleyboinc_client>= 0 < 6.2.14-36.2.14-3
berkeleyboinc_client>= 0 < 6.2.14-36.2.14-3
berkeleyboinc_client>= 0 < 6.2.14-36.2.14-3
debianbind9< bind9 1:9.5.1.dfsg.P1-1 (bookworm)bind9 1:9.5.1.dfsg.P1-1 (bookworm)
debianbind9
debianboinc< boinc 6.2.14-3 (bookworm)boinc 6.2.14-3 (bookworm)
debianerlang
debianevolution-data-server< evolution-data-server 2.24.5-2 (bookworm)evolution-data-server 2.24.5-2 (bookworm)
debianlasso< lasso 2.2.1-2 (bookworm)lasso 2.2.1-2 (bookworm)
debianlibcrypt-openssl-dsa-perl< libcrypt-openssl-dsa-perl 0.13-4 (bookworm)libcrypt-openssl-dsa-perl 0.13-4 (bookworm)
debianm2crypto
debianntp< ntp 1:4.2.4p4+dfsg-8 (bullseye)ntp 1:4.2.4p4+dfsg-8 (bullseye)
debianopenssl< openssl 0.9.8g-15 (bookworm)openssl 0.9.8g-15 (bookworm)
eideidlib<= 2.6.0
entrouvertlasso<= 2.2.1-0
entrouvertlasso
entrouvertlasso
entrouvertlasso>= 0 < 2.2.1-22.2.1-2
entrouvertlasso>= 0 < 2.2.1-22.2.1-2
entrouvertlasso>= 0 < 2.2.1-22.2.1-2
entrouvertlasso>= 0 < 2.2.1-22.2.1-2

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.