global security disclosure
Showing 1 - 1 of 1 RSS Feed

Files

OpenSSL Security Advisory 07-Jan-2009
Posted Jan 7, 2009
Site openssl.org

Several functions inside OpenSSL incorrectly checked the result aftercalling the EVP_VerifyFinal function, allowing a malformed signatureto be treated as a good signature rather than as an error. This issueaffected the signature checks on DSA and ECDSA keys used withSSL/TLS.One way to exploit this flaw would be for a remote attacker who is incontrol of a malicious server or who can use a 'man in the middle'attack to present a malformed SSL/TLS signature from a certificate chainto a vulnerable client, bypassing validation.

tags | advisory, remote
advisories | CVE-2008-5077
MD5 | 5ff1f702db3b6ad0f391aaa8dc65fdbb
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close