CVE-2009-0265
published 2009-01-26CVE-2009-0265: Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows…
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.47%
83.5th percentile
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | <= 9.6.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.8LOW
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-0265: bind9 - Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check...
vendor_debian·2009·CVSS 5.8
CVE-2009-0265 [MEDIUM] CVE-2009-0265: bind9 - Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check...
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Red Hat
CVE-2009-0265: Internet Systems Consortium (ISC) BIND 9
vendor_redhat·CVSS 5.8
CVE-2009-0265 [MEDIUM] CVE-2009-0265: Internet Systems Consortium (ISC) BIND 9
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
Statement: Not vulnerable. This issue did not affect the versions of BIND as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
GHSA
GHSA-mrwj-9mpp-w94q: Internet Systems Consortium (ISC) BIND 9
ghsa_unreviewed·2022-05-02·CVSS 5.8
CVE-2009-0265 [MEDIUM] CWE-252 GHSA-mrwj-9mpp-w94q: Internet Systems Consortium (ISC) BIND 9
Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Improper Following of a Certificate's Chain of Trust
mitre_cwe
CWE-296 Improper Following of a Certificate's Chain of Trust
CWE-296: Improper Following of a Certificate's Chain of Trust
The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate, resulting in incorrect trust of any resource that is associated with that certificate.
If a system does not follow the chain of trust of a certificate to a root server, the certificate loses all usefulness as a metric of trust. Essentially, the trust gained from a certificate is derived from a chain of trust -- with a reputable trusted entity at the end of that list. The end user must trust that reputable source, and this reputable source must vouch for the resource in question through the medium of the certificate. In some cases, this trust traverses several entities who vouch for one another. The enti
CWE
Improper Certificate Validation
mitre_cwe
CWE-295 Improper Certificate Validation
CWE-295: Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
Background: A certificate is a token that associates an identity (principal) to a cryptographic key. Certificates can be used to check if a public key belongs to the assumed owner.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Implementation
Note: When the product uses certificate pinning, the developer might not properly validate all relevant components of the certificate before pinning the certificate. This can make it difficult or expensive to test after the pinning is complete.
Common Consequences:
Scope: Integrity, Authentication. Im
http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33http://secunia.com/advisories/33559http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.540362http://www.mandriva.com/security/advisories?name=MDVSA-2009:037http://www.vupen.com/english/advisories/2009/0043https://www.isc.org/node/373http://groups.google.com/group/comp.protocols.dns.bind/browse_thread/thread/49ef622c8329fd33http://secunia.com/advisories/33559http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.540362http://www.mandriva.com/security/advisories?name=MDVSA-2009:037http://www.vupen.com/english/advisories/2009/0043https://www.isc.org/node/373
2009-01-26
Published