.:[ packet storm ]:.
                         
all things security
all things security

 ///  File Name:secadv_20090107.txt
Description:
Several functions inside OpenSSL incorrectly checked the result aftercalling the EVP_VerifyFinal function, allowing a malformed signatureto be treated as a good signature rather than as an error. This issueaffected the signature checks on DSA and ECDSA keys used withSSL/TLS.One way to exploit this flaw would be for a remote attacker who is incontrol of a malicious server or who can use a 'man in the middle'attack to present a malformed SSL/TLS signature from a certificate chainto a vulnerable client, bypassing validation.
Homepage:http://www.openssl.org/
Related File:oCERT-2008-016.txt
File Size:7906
Related CVE(s):CVE-2008-5077
Last Modified:Jan 7 15:21:31 2009
MD5 Checksum:5ff1f702db3b6ad0f391aaa8dc65fdbb

 .:. Back