5
CVSSv2

CVE-2009-0047

Published: 07/01/2009 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Gale 0.99 and previous versions does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote malicious users to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

Vulnerable Product Search on Vulmon Subscribe to Product

gale gale 0.91a

gale gale 0.91b

gale gale 0.19a

gale gale 0.19b

gale gale 0.90c

gale gale 0.21

gale gale 0.18c

gale gale 0.90a

gale gale 0.90b

gale gale 0.18

gale gale 0.18b

gale gale 0.15c

gale gale

gale gale 0.91

gale gale 0.20a

gale gale 0.19

gale gale 0.16

gale gale 0.16a

gale gale 0.15

gale gale 0.15b

gale gale 0.17

gale gale 0.17a