CVE-2009-0126
published 2009-01-15CVE-2009-0126: The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.42%
82.5th percentile
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| berkeley | boinc_client | — | — |
| berkeley | boinc_client | — | — |
| berkeley | boinc_client | >= 0 < 6.2.14-3 | 6.2.14-3 |
| berkeley | boinc_client | >= 0 < 6.2.14-3 | 6.2.14-3 |
| berkeley | boinc_client | >= 0 < 6.2.14-3 | 6.2.14-3 |
| berkeley | boinc_client | >= 0 < 6.2.14-3 | 6.2.14-3 |
| debian | boinc | < boinc 6.2.14-3 (bookworm) | boinc 6.2.14-3 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gpcp-59gr-fj3v: The decrypt_public function in lib/crypt
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0126 [MEDIUM] CWE-287 GHSA-gpcp-59gr-fj3v: The decrypt_public function in lib/crypt
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
OSV
CVE-2009-0126: The decrypt_public function in lib/crypt
osv·2009-01-15·CVSS 5.8
CVE-2009-0126 [MEDIUM] CVE-2009-0126: The decrypt_public function in lib/crypt
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Red Hat
boinc-client: Does not check the RSA_public_decrypt() return value.
vendor_redhat·2009-01-11·CVSS 5.8
CVE-2009-0126 [MEDIUM] boinc-client: Does not check the RSA_public_decrypt() return value.
boinc-client: Does not check the RSA_public_decrypt() return value.
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Debian
CVE-2009-0126: boinc - The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infr...
vendor_debian·2009·CVSS 5.8
CVE-2009-0126 [MEDIUM] CVE-2009-0126: boinc - The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infr...
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scope: local
bookworm: resolved (fixed in 6.2.14-3)
bullseye: resolved (fixed in 6.2.14-3)
forky: resolved (fixed in 6.2.14-3)
sid: resolved (fixed in 6.2.14-3)
trixie: resolved (fixed in 6.2.14-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3722 KVM: Check cpl before emulating debug register access
bugzilla·2009-10-29·CVSS 7.1
CVE-2009-3722 [HIGH] CVE-2009-3722 KVM: Check cpl before emulating debug register access
CVE-2009-3722 KVM: Check cpl before emulating debug register access
Quote from the upstream commit:
Debug registers may only be accessed from cpl 0. Unfortunately, vmx will code to emulate the instruction even though it was issued from guest userspace, possibly leading to an unexpected trap later.
Introduced in v2.6.30-rc1; Fixed in v2.6.32-rc1.
http://git.kernel.org/linus/0a79b009525b160081d75cef5dbf45817956acf2
Discussion:
None of our kernels is affected by this vulnerability. Closing this bug as NOTABUG.
---
Also fixed in 2.6.30.9 and 2.6.31.1
---
The kvm package in RHEL 5.[45] is in fact vulnerable.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0126 https://rhn.redhat.com/errata/RHSA-2010-0126.html
---
This issue has be
Bugzilla
CVE-2009-0126 boinc-client: Does not check the RSA_public_decrypt() return value.
bugzilla·2009-01-12·CVSS 5.8
CVE-2009-0126 [MEDIUM] CVE-2009-0126 boinc-client: Does not check the RSA_public_decrypt() return value.
CVE-2009-0126 boinc-client: Does not check the RSA_public_decrypt() return value.
The Berkeley Open Infrastructure for Network Computing (BOINC) client software
incorrectly checked the result after calling the RSA_public_decrypt function,
allowing a malformed signature to be treated as a good signature rather
than as an error. This issue affected the signature checks on RSA keys used
with SSL/TLS.
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521
This issue is related with recent OpenSSL's CVE-2008-5077 flaw.
Discussion:
This issue affects all versions of the boinc-client package, as shipped
with Fedora updates of 9, 10 and devel.
Please fix.
Relevant part of the code (lib/crypt.C):
228 int decrypt_public(R_RSA_PUBLIC_KEY& key, DATA_BLOCK& in, DATA_BLOCK& out) {
2
http://boinc.berkeley.edu/trac/changeset/16883http://boinc.berkeley.edu/trac/ticket/823http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://openwall.com/lists/oss-security/2009/01/12/4http://secunia.com/advisories/33806http://secunia.com/advisories/33828https://bugzilla.redhat.com/show_bug.cgi?id=479664https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00034.htmlhttp://boinc.berkeley.edu/trac/changeset/16883http://boinc.berkeley.edu/trac/ticket/823http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.htmlhttp://openwall.com/lists/oss-security/2009/01/12/4http://secunia.com/advisories/33806http://secunia.com/advisories/33828https://bugzilla.redhat.com/show_bug.cgi?id=479664https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00034.html
2009-01-15
Published