CVE-2008-5077
07.01.2009, 17:30
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.Enginsight
Vendor | Product | Version |
---|---|---|
openssl | openssl | 𝑥 ≤ 0.9.8h |
openssl | openssl | 0.9.1c:c |
openssl | openssl | 0.9.2b:b |
openssl | openssl | 0.9.3 |
openssl | openssl | 0.9.3a:a |
openssl | openssl | 0.9.4 |
openssl | openssl | 0.9.5 |
openssl | openssl | 0.9.5:beta1 |
openssl | openssl | 0.9.5:beta2 |
openssl | openssl | 0.9.5a:a |
openssl | openssl | 0.9.5a:a |
openssl | openssl | 0.9.5a:a |
openssl | openssl | 0.9.6 |
openssl | openssl | 0.9.6:beta1 |
openssl | openssl | 0.9.6:beta2 |
openssl | openssl | 0.9.6:beta3 |
openssl | openssl | 0.9.6a:a |
openssl | openssl | 0.9.6a:a |
openssl | openssl | 0.9.6a:a |
openssl | openssl | 0.9.6a:a |
openssl | openssl | 0.9.6b:b |
openssl | openssl | 0.9.6c:c |
openssl | openssl | 0.9.6d:d |
openssl | openssl | 0.9.6e:e |
openssl | openssl | 0.9.6f:f |
openssl | openssl | 0.9.6g:g |
openssl | openssl | 0.9.6h:h |
openssl | openssl | 0.9.6i:i |
openssl | openssl | 0.9.6j:j |
openssl | openssl | 0.9.6k:k |
openssl | openssl | 0.9.6l:l |
openssl | openssl | 0.9.6m:m |
openssl | openssl | 0.9.7 |
openssl | openssl | 0.9.7:beta1 |
openssl | openssl | 0.9.7:beta2 |
openssl | openssl | 0.9.7:beta3 |
openssl | openssl | 0.9.7:beta4 |
openssl | openssl | 0.9.7:beta5 |
openssl | openssl | 0.9.7:beta6 |
openssl | openssl | 0.9.7a:a |
openssl | openssl | 0.9.7b:b |
openssl | openssl | 0.9.7c:c |
openssl | openssl | 0.9.7d:d |
openssl | openssl | 0.9.7e:e |
openssl | openssl | 0.9.7f:f |
openssl | openssl | 0.9.7g:g |
openssl | openssl | 0.9.7h:h |
openssl | openssl | 0.9.7i:i |
openssl | openssl | 0.9.7j:j |
openssl | openssl | 0.9.7k:k |
openssl | openssl | 0.9.7l:l |
openssl | openssl | 0.9.8 |
openssl | openssl | 0.9.8a:a |
openssl | openssl | 0.9.8b:b |
openssl | openssl | 0.9.8c:c |
openssl | openssl | 0.9.8d:d |
openssl | openssl | 0.9.8e:e |
openssl | openssl | 0.9.8f:f |
openssl | openssl | 0.9.8g:g |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References