OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssl | — | Apply OS X security update 2009-002Upgrade macOS to the latest version | Dec 16, 2011 | Jan 7, 2009 |
| Centos_linux | — | Upgrade openssl-develUpgrade openssl096bUpgrade openssl-perlUpgrade openssl | Dec 1, 2016 | Jan 7, 2009 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Jan 7, 2009 |
| Gentoo Linux | — | Upgrade dev-libs/openssl.Upgrade net-misc/ntp. | Oct 30, 2017 | Jan 7, 2009 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Jan 7, 2009 |
| Hpux | — | Update fips_1_1_2.FIPS-DOC to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-INC to the latest versionUpdate fips_1_1_2.FIPS-RUN to the latest versionUpdate fips_1_2.FIPS-CONF to the latest versionUpdate openssl.OPENSSL-MIS to the latest versionUpdate fips_1_1_2.FIPS-SRC to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate fips_1_2.FIPS-LIB to the latest versionUpdate fips_1_2.FIPS-DOC to the latest versionUpdate fips_1_1_2.FIPS-LIB to the latest versionUpdate fips_1_1_2.FIPS-MIS to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate fips_1_1_2.FIPS-CONF to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate fips_1_2.FIPS-MAN to the latest versionUpdate fips_1_2.FIPS-RUN to the latest versionUpdate fips_1_2.FIPS-SRC to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate fips_1_1_2.FIPS-INC to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate fips_1_1_2.FIPS-MAN to the latest versionUpdate fips_1_2.FIPS-MIS to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate fips_1_2.FIPS-INC to the latest version | Aug 11, 2017 | Jan 7, 2009 |
| Oracle_linux | — | Upgrade openssl-perlUpgrade openssl097aUpgrade openssl-develUpgrade openssl | Oct 16, 2024 | Jan 7, 2009 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 6.3R3Update Pulse Connect Secure to version 6.0R10Update Pulse Connect Secure to version 6.2R4Update Pulse Connect Secure to version 6.1R7 | Oct 28, 2020 | Jan 7, 2009 |
| Suse | — | Upgrade libopenssl-fips-providerUpgrade libopenssl-1_1-develUpgrade libopenssl0_9_8Upgrade libopenssl-1_1-devel-32bitUpgrade libopenssl1-develUpgrade libopenssl0_9_8-x86Upgrade libopenssl1_0_0Upgrade openssl-docUpgrade libopenssl1_0_0-hmac-32bitUpgrade libopenssl1_0_0-hmacUpgrade libopenssl1_0_0-32bitUpgrade openssl-1_0_0Upgrade boinc-clientUpgrade openssl-1_0_0-docUpgrade libopenssl-1_0_0-develUpgrade libopenssl0_9_8-32bitUpgrade opensslUpgrade libopenssl0_9_8-hmacUpgrade libopenssl1_1-32bitUpgrade libopenssl1_1Upgrade openssl1Upgrade libopenssl-develUpgrade openssl-1_1Upgrade libopenssl1_1-hmac-32bitUpgrade libopenssl1_1-hmacUpgrade openssl1-docUpgrade libopenssl0_9_8-hmac-32bitUpgrade boinc-client-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libssl0.9.8Upgrade openssl | Nov 8, 2024 | Jan 7, 2009 |
| Vmsa 2009 0004 3 Updated Openssl Package | — | Upgrade VMware ESX 3.5 to build number 158874Upgrade VMware ESX 4.0 to build number 219382 | Sep 2, 2010 | Jan 7, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub