CVE-2008-5077

CVSS V2 Medium 5.8 CVSS V3 None
Description
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
Overview
  • CVE ID
  • CVE-2008-5077
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Modified
  • Published Version
  • 2009-01-07T17:30:00
  • Last Modified Date
  • 2018-10-11T20:53:40
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* 1 OR 0.9.8h
cpe:2.3:a:openssl:openssl:0.9.1c:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.2b:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.3a:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.5:beta1:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.5:beta2:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.5a:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.5a:beta1:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.5a:beta2:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6:beta1:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6:beta2:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6:beta3:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6a:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6a:beta1:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6a:beta2:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6a:beta3:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6b:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6c:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6d:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6e:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6f:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6g:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6h:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6i:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6j:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6k:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6l:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.6m:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7:beta1:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7:beta2:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7:beta3:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7:beta4:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7:beta5:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7:beta6:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7a:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7b:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7c:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7d:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7e:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7f:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7g:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7h:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7i:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7j:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7k:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.7l:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:N/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 5.8
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 4.9
References
Reference URL Reference Tags
http://www.ocert.org/advisories/ocert-2008-016.html
http://secunia.com/advisories/33338 Vendor Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-66-250826-1
http://voodoo-circle.sourceforge.net/sa/sa-20090123-01.html
http://secunia.com/advisories/33765 Vendor Advisory
http://secunia.com/advisories/33673 Vendor Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.544796
http://secunia.com/advisories/33557 Vendor Advisory
http://secunia.com/advisories/33436 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200902-02.xml
http://support.avaya.com/elmodocs2/security/ASA-2009-038.htm
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=837653
http://www.vupen.com/english/advisories/2009/0558 Vendor Advisory
http://www.vmware.com/security/advisories/VMSA-2009-0004.html
http://marc.info/?l=bugtraq&m=123859864430555&w=2
http://www.vupen.com/english/advisories/2009/0913 Vendor Advisory
http://www.vupen.com/english/advisories/2009/0904 Vendor Advisory
http://secunia.com/advisories/34211 Vendor Advisory
http://support.apple.com/kb/HT3549
http://www.vupen.com/english/advisories/2009/1297 Vendor Advisory
http://secunia.com/advisories/35074 Vendor Advisory
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://marc.info/?l=bugtraq&m=124277349419254&w=2
http://www.vupen.com/english/advisories/2009/1338 Vendor Advisory
http://secunia.com/advisories/35108 Vendor Advisory
http://secunia.com/advisories/39005 Vendor Advisory
http://www.vupen.com/english/advisories/2009/0040 Vendor Advisory
http://www.vupen.com/english/advisories/2009/0289 Vendor Advisory
http://www.vupen.com/english/advisories/2009/0362 Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html
http://www.securitytracker.com/id?1021523
http://www.redhat.com/support/errata/RHSA-2009-0004.html
http://secunia.com/advisories/33394
http://www.securityfocus.com/bid/33150
http://www.openssl.org/news/secadv_20090107.txt
http://marc.info/?l=bugtraq&m=127678688104458&w=2
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9155
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6380
https://usn.ubuntu.com/704-1/
http://www.securityfocus.com/archive/1/502322/100/0/threaded
http://www.securityfocus.com/archive/1/499827/100/0/threaded
History
Created Old Value New Value Data Type Notes
2022-05-10 18:27:35 Added to TrackCVE