CVE-2008-5077

Publication date 7 January 2009

Last updated 24 July 2024


Ubuntu priority

OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

Status

Package Ubuntu Release Status
openssl 8.10 intrepid
Fixed 0.9.8g-10.1ubuntu2.1
8.04 LTS hardy
Fixed 0.9.8g-4ubuntu3.4
7.10 gutsy
Fixed 0.9.8e-5ubuntu3.3
6.06 LTS dapper
Fixed 0.9.8a-7ubuntu0.6

References

Related Ubuntu Security Notices (USN)

    • USN-704-1
    • OpenSSL vulnerability
    • 7 January 2009

Other references