2.6
CVSSv2

CVE-2009-0591

Published: 27/03/2009 Updated: 17/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The CMS_verify function in OpenSSL 0.9.8h up to and including 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote malicious users to repudiate a signature that originally appeared to be valid but was actually invalid.

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 0.9.8h

openssl openssl 0.9.8i

openssl openssl 0.9.8j