cbcvebase.
CVE-2009-0025
published 2009-01-07

CVE-2009-0025: BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianbind9< bind9 1:9.5.1.dfsg.P1-1 (bookworm)bind9 1:9.5.1.dfsg.P1-1 (bookworm)
debianbind9
iscbind<= 9.6.0
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind
iscbind

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd6.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.8MEDIUM