CVE-2009-0025
published 2009-01-07CVE-2009-0025: BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to…
PriorityP338medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
6.86%
93.3th percentile
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.5.1.dfsg.P1-1 (bookworm) | bind9 1:9.5.1.dfsg.P1-1 (bookworm) |
| debian | bind9 | — | — |
| isc | bind | <= 9.6.0 | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
BSD
FreeBSD-SA-09:04.bind: BIND DNSSEC incorrect checks for malformed signatures
bsd_advisories·2009-01-13·CVSS 6.8
CVE-2009-0025 [MEDIUM] FreeBSD-SA-09:04.bind: BIND DNSSEC incorrect checks for malformed signatures
FreeBSD-SA-09:04.bind Security Advisory
The FreeBSD Project
Topic: BIND DNSSEC incorrect checks for malformed signatures
Category: contrib
Module: bind
Announced: 2009-01-13
Credits: Google Security Team
Affects: All supported FreeBSD versions
Corrected: 2009-01-10 03:00:21 UTC (RELENG_7, 7.1-STABLE)
2009-01-13 21:19:27 UTC (RELENG_7_1, 7.1-RELEASE-p2)
2009-01-13 21:19:27 UTC (RELENG_7_0, 7.0-RELEASE-p9)
2009-01-10 04:30:27 UTC (RELENG_6, 6.4-STABLE)
2009-01-13 21:19:27 UTC (RELENG_6_4, 6.4-RELEASE-p3)
2009-01-13 21:19:27 UTC (RELENG_6_3, 6.3-RELEASE-p9)
CVE Name: CVE-2009-0025
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
BIND 9 is an implementation
Ubuntu
Bind vulnerability
vendor_ubuntu·2009-01-09
CVE-2009-0025 Bind vulnerability
Title: Bind vulnerability
Summary: Bind vulnerability
It was discovered that Bind did not properly perform signature verification.
When DNSSEC with DSA signatures are in use, a remote attacker could exploit
this to bypass signature validation to spoof DNS entries and poison DNS
caches. Among other things, this could lead to misdirected email and web
traffic.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
bind: DSA_do_verify() returns check issue
vendor_redhat·2009-01-07·CVSS 5.8
CVE-2009-0025 [MEDIUM] bind: DSA_do_verify() returns check issue
bind: DSA_do_verify() returns check issue
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Debian
CVE-2009-0265: bind9 - Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check...
vendor_debian·2009·CVSS 5.8
CVE-2009-0265 [MEDIUM] CVE-2009-0265: bind9 - Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check...
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2009-0025: bind9 - BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return ...
vendor_debian·2009·CVSS 5.8
CVE-2009-0025 [MEDIUM] CVE-2009-0025: bind9 - BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return ...
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scope: local
bookworm: resolved (fixed in 1:9.5.1.dfsg.P1-1)
bullseye: resolved (fixed in 1:9.5.1.dfsg.P1-1)
forky: resolved (fixed in 1:9.5.1.dfsg.P1-1)
sid: resolved (fixed in 1:9.5.1.dfsg.P1-1)
trixie: resolved (fixed in 1:9.5.1.dfsg.P1-1)
Red Hat
CVE-2009-0265: Internet Systems Consortium (ISC) BIND 9
vendor_redhat·CVSS 5.8
CVE-2009-0265 [MEDIUM] CVE-2009-0265: Internet Systems Consortium (ISC) BIND 9
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Statement: Not vulnerable. This issue did not affect the versions of BIND as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
GHSA
GHSA-hcwf-6ghh-6m6f: BIND 9
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0025 [MEDIUM] CWE-287 GHSA-hcwf-6ghh-6m6f: BIND 9
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
GHSA
GHSA-mrwj-9mpp-w94q: Internet Systems Consortium (ISC) BIND 9
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0265 [MEDIUM] CWE-252 GHSA-mrwj-9mpp-w94q: Internet Systems Consortium (ISC) BIND 9
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
OSV
CVE-2009-0025: BIND 9
osv·2009-01-07·CVSS 5.8
CVE-2009-0025 [MEDIUM] CVE-2009-0025: BIND 9
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
No detection rules found.
No public exploits indexed.
Bugzilla
Moodle: Multiple security fixes in 1.9.7 and 1.8.11 upstream releases
bugzilla·2009-12-06·CVSS 6.8
CVE-2009-4297 [MEDIUM] Moodle: Multiple security fixes in 1.9.7 and 1.8.11 upstream releases
Moodle: Multiple security fixes in 1.9.7 and 1.8.11 upstream releases
Moodle upstream has released latest stable versions (1.9.7 and 1.8.11),
fixing multiple security issues.
The list for 1.9.7 release:
Security issues
* MSA-09-0022 - CVE-2009-4297 Multiple CSRF problems fixed
* MSA-09-0023 - CVE-2009-4298 Fixed user account disclosure in LAMS module
* MSA-09-0024 - CVE-2009-4299 Fixed insufficient access control in
Glossary module
* MSA-09-0025 - CVE-2009-4300 Unneeded MD5 hashes removed from user table
* MSA-09-0026 - CVE-2009-4301 Fixed invalid application access control
in MNET interface
* MSA-09-0027 - CVE-2009-4302 Ensured login information is always sent
secured when using SSL for logins
* MSA-09-0028 - CVE-2009-4303 Passwords and secrets are no longer ever
saved in backups, new
Bugzilla
CVE-2009-0025 bind: DSA_do_verify() returns check issue
bugzilla·2009-01-06·CVSS 5.8
CVE-2009-0025 [MEDIUM] CVE-2009-0025 bind: DSA_do_verify() returns check issue
CVE-2009-0025 bind: DSA_do_verify() returns check issue
Gave CVE-2009-0025 to ISC for their advisory.
Discussion:
Now public, removing embargo:
https://www.isc.org/node/373
---
nternet Systems Consortium Security Advisory.
BIND: EVP_VerifyFinal() and DSA_do_verify() return checks.
7 January 2009
Versions affected:
BIND 9.0 (all versions)
BIND 9.1 (all versions)
BIND 9.2 (all versions)
BIND 9.3.0, 9.3.1, 9.3.2, 9.3.3, 9.3.4, 9.3.5, 9.3.6
BIND 9.4.0, 9.4.1, 9.4.2, 9.4.3
BIND 9.5.0, 9.5.1
BIND 9.6.0
Severity: Low.
Description:
Return values from OpenSSL library functions EVP_VerifyFinal()
and DSA_do_verify() were not checked properly.
Impact:
It is theoretically possible to spoof answers returned from
zones using the DNSKEY algorithms DSA (3) and NSEC3DSA (6).
Workaround:
BIND 9
http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://marc.info/?l=bugtraq&m=141879471518471&w=2http://secunia.com/advisories/33494http://secunia.com/advisories/33546http://secunia.com/advisories/33551http://secunia.com/advisories/33559http://secunia.com/advisories/33683http://secunia.com/advisories/33882http://secunia.com/advisories/35074http://security.freebsd.org/advisories/FreeBSD-SA-09:04.bind.aschttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.540362http://sunsolve.sun.com/search/document.do?assetkey=1-26-250846-1http://support.apple.com/kb/HT3549http://support.avaya.com/elmodocs2/security/ASA-2009-045.htmhttp://wiki.rpath.com/Advisories:rPSA-2009-0009http://www.ocert.org/advisories/ocert-2008-016.htmlhttp://www.openbsd.org/errata44.html#008_bindhttp://www.securityfocus.com/archive/1/499827/100/0/threadedhttp://www.securityfocus.com/archive/1/500207/100/0/threadedhttp://www.securityfocus.com/archive/1/502322/100/0/threadedhttp://www.securityfocus.com/bid/33151http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0004.htmlhttp://www.vupen.com/english/advisories/2009/0043http://www.vupen.com/english/advisories/2009/0366http://www.vupen.com/english/advisories/2009/0904http://www.vupen.com/english/advisories/2009/1297https://issues.rpath.com/browse/RPL-2938https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10879https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5569https://www.isc.org/software/bind/advisories/cve-2009-0025https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00393.htmlhttp://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33http://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://marc.info/?l=bugtraq&m=141879471518471&w=2http://secunia.com/advisories/33494http://secunia.com/advisories/33546http://secunia.com/advisories/33551http://secunia.com/advisories/33559http://secunia.com/advisories/33683http://secunia.com/advisories/33882http://secunia.com/advisories/35074http://security.freebsd.org/advisories/FreeBSD-SA-09:04.bind.aschttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.540362http://sunsolve.sun.com/search/document.do?assetkey=1-26-250846-1http://support.apple.com/kb/HT3549http://support.avaya.com/elmodocs2/security/ASA-2009-045.htmhttp://wiki.rpath.com/Advisories:rPSA-2009-0009http://www.ocert.org/advisories/ocert-2008-016.htmlhttp://www.openbsd.org/errata44.html#008_bindhttp://www.securityfocus.com/archive/1/499827/100/0/threadedhttp://www.securityfocus.com/archive/1/500207/100/0/threadedhttp://www.securityfocus.com/archive/1/502322/100/0/threadedhttp://www.securityfocus.com/bid/33151http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vmware.com/security/advisories/VMSA-2009-0004.htmlhttp://www.vupen.com/english/advisories/2009/0043http://www.vupen.com/english/advisories/2009/0366http://www.vupen.com/english/advisories/2009/0904http://www.vupen.com/english/advisories/2009/1297https://issues.rpath.com/browse/RPL-2938https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10879https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5569https://www.isc.org/software/bind/advisories/cve-2009-0025https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00393.html
2009-01-07
Published