Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4q4m-qx69-vcgq

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

EPSS

Процентиль: 87%
0.03366
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 16 лет назад

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

redhat
больше 16 лет назад

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

nvd
больше 16 лет назад

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

debian
больше 16 лет назад

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly ...

oracle-oval
больше 16 лет назад

ELSA-2009-0046: ntp security update (MODERATE)

EPSS

Процентиль: 87%
0.03366
Низкий

Дефекты

CWE-287