OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssl | — | Apply OS X security update 2009-002Upgrade macOS to the latest version | Dec 16, 2011 | Jan 7, 2009 |
| Centos_linux | — | Upgrade openssl-perlUpgrade opensslUpgrade openssl096bUpgrade openssl-devel | Dec 1, 2016 | Jan 7, 2009 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Jan 7, 2009 |
| Gentoo Linux | — | Upgrade dev-libs/openssl.Upgrade net-misc/ntp. | Oct 30, 2017 | Jan 7, 2009 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Jan 7, 2009 |
| Hpux | — | Update openssl.OPENSSL-MIS to the latest versionUpdate fips_1_1_2.FIPS-SRC to the latest versionUpdate fips_1_1_2.FIPS-DOC to the latest versionUpdate fips_1_2.FIPS-CONF to the latest versionUpdate fips_1_1_2.FIPS-RUN to the latest versionUpdate fips_1_1_2.FIPS-LIB to the latest versionUpdate fips_1_2.FIPS-DOC to the latest versionUpdate fips_1_2.FIPS-LIB to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate fips_1_1_2.FIPS-INC to the latest versionUpdate fips_1_1_2.FIPS-CONF to the latest versionUpdate fips_1_1_2.FIPS-MIS to the latest versionUpdate fips_1_2.FIPS-MIS to the latest versionUpdate fips_1_2.FIPS-SRC to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate fips_1_2.FIPS-MAN to the latest versionUpdate fips_1_1_2.FIPS-MAN to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate fips_1_2.FIPS-INC to the latest versionUpdate fips_1_2.FIPS-RUN to the latest versionUpdate openssl.OPENSSL-CER to the latest version | Aug 11, 2017 | Jan 7, 2009 |
| Oracle_linux | — | Upgrade openssl097aUpgrade openssl-perlUpgrade openssl-develUpgrade openssl | Oct 16, 2024 | Jan 7, 2009 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 6.1R7Update Pulse Connect Secure to version 6.3R3Update Pulse Connect Secure to version 6.0R10Update Pulse Connect Secure to version 6.2R4 | Oct 28, 2020 | Jan 7, 2009 |
| Suse | — | Upgrade libopenssl0_9_8Upgrade openssl-develUpgrade openssl-docUpgrade compat-openssl097gUpgrade compat-openssl097g-x86Upgrade openssl-devel-64bitUpgrade libopenssl-develUpgrade compat-openssl097g-64bitUpgrade compat-openssl097g-32bitUpgrade openssl-32bitUpgrade openssl-devel-32bitUpgrade opensslUpgrade openssl-64bitUpgrade openssl-x86Upgrade libopenssl0_9_8-64bitUpgrade libopenssl0_9_8-32bitUpgrade sap-aio-releaseUpgrade openssl-certs | Feb 17, 2015 | Jan 7, 2009 |
| Ubuntu | — | Upgrade opensslUpgrade libssl0.9.8 | Nov 8, 2024 | Jan 7, 2009 |
| Vmsa 2009 0004 3 Updated Openssl Package | — | Upgrade VMware ESX 3.5 to build number 158874Upgrade VMware ESX 4.0 to build number 219382 | Sep 2, 2010 | Jan 7, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub