MNBSD-2009-1: OpenSSL improperly accepts invalid certificate signatures as valid

Severity: Unknown

Affected Package: openssl

Summary: OpenSSL improperly accepts invalid certificate signatures as valid

Description

OpenSSL did not properly check the return value from EVP_VerifyFinal, so applications using OpenSSL could interpret a malformed DSA/ECDSA signature or certificate as valid. The fix was applied to MidnightBSD 0.2.1 and 0.3-CURRENT. This corresponds to FreeBSD-SA-09:03.openssl.

Affected Versions

openssl

Recommendations

No specific recommendations provided.

References

Additional Information

Aliases: CVE-2008-5077

Published: January 10, 2009
Last Modified: January 10, 2009