CVE-2009-0046

Severity
5.0MEDIUM
EPSS
0.1%
top 74.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 7
Latest updateMay 2

Description

Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDsun/grid_engine5.3+1

🔴Vulnerability Details

2
GHSA
GHSA-9wmh-wp74-54qv: Sun GridEngine 52022-05-02
CVEList
CVE-2009-0046: Sun GridEngine 52009-01-07

📋Vendor Advisories

1
Red Hat
kernel: use flag in do_coredump()2009-11-12

💬Community

1
Bugzilla
CVE-2009-4141 kernel: create_elf_tables can leave urandom in a bad state2009-12-15
CVE-2009-0046 (MEDIUM CVSS 5) | Sun GridEngine 5.3 and earlier does | cvebase.io