Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-0021

Опубликовано: 07 янв. 2009
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=476807ntp incorrectly checks for malformed signatures

EPSS

Процентиль: 89%
0.04642
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 17 лет назад

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

nvd
почти 17 лет назад

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

debian
почти 17 лет назад

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly ...

github
больше 3 лет назад

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

oracle-oval
почти 17 лет назад

ELSA-2009-0046: ntp security update (MODERATE)

EPSS

Процентиль: 89%
0.04642
Низкий

4.3 Medium

CVSS2