← Back

CVE-2009-0047

nvd nist
Published: Jan 7, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

Affected (22)

Products: Gale: Gale
1 product
Gale
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Gale
Up to 0.99
Version 0.15
Version 0.15b
Version 0.15c
Version 0.16
Version 0.16a
Version 0.17
Version 0.17a
Version 0.18
Version 0.18b
Version 0.18c
Version 0.19
Version 0.19a
Version 0.19b
Version 0.20a
Version 0.21
Version 0.90a
Version 0.90b
Version 0.90c
Version 0.91
Version 0.91a
Version 0.91b

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.