5

CVE-2009-0047

Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GaleGale Version <= 0.99
GaleGale Version0.15
GaleGale Version0.15b
GaleGale Version0.15c
GaleGale Version0.16
GaleGale Version0.16a
GaleGale Version0.17
GaleGale Version0.17a
GaleGale Version0.18
GaleGale Version0.18b
GaleGale Version0.18c
GaleGale Version0.19
GaleGale Version0.19a
GaleGale Version0.19b
GaleGale Version0.20a
GaleGale Version0.21
GaleGale Version0.90a
GaleGale Version0.90b
GaleGale Version0.90c
GaleGale Version0.91
GaleGale Version0.91a
GaleGale Version0.91b
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.223
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.