Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5fwv-px3v-6qxv

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

Ссылки

EPSS

Процентиль: 77%
0.01066
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 16 лет назад

OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

redhat
больше 16 лет назад

OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

nvd
больше 16 лет назад

OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

debian
больше 16 лет назад

OpenSSL 0.9.8i and earlier does not properly check the return value fr ...

oracle-oval
больше 16 лет назад

ELSA-2009-0004: openssl security update (IMPORTANT)

EPSS

Процентиль: 77%
0.01066
Низкий

Дефекты

CWE-20