CVE-2009-0046
published 2009-01-07CVE-2009-0046: Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass…
PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.18%
64.1th percentile
Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | grid_engine | <= 5.3 | — |
| sun | grid_engine | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wmh-wp74-54qv: Sun GridEngine 5
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0046 [MEDIUM] CWE-287 GHSA-9wmh-wp74-54qv: Sun GridEngine 5
Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Red Hat
kernel: use flag in do_coredump()
vendor_redhat·2009-11-12·CVSS 7.5
CVE-2006-6304 [HIGH] kernel: use flag in do_coredump()
kernel: use flag in do_coredump()
The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent attackers to modify arbitrary files via a rewrite attack during a core dump.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG. Shipped kernels do not include upstream commit d025c9db that introduced the problem.
This upstream commit was backported in Red Hat Enterprise Linux 5 via RHSA-2009:0225. It was later reported and addressed in Red Hat Enterprise Linux 5 via RHSA-2010:0046.
No detection rules found.
No public exploits indexed.
http://www.ocert.org/advisories/ocert-2008-016.htmlhttp://www.securityfocus.com/archive/1/499827/100/0/threadedhttp://www.vupen.com/english/advisories/2009/0045http://www.ocert.org/advisories/ocert-2008-016.htmlhttp://www.securityfocus.com/archive/1/499827/100/0/threadedhttp://www.vupen.com/english/advisories/2009/0045
2009-01-07
Published