The CMS_verify function in OpenSSL 0.9.8h up to and including 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote malicious users to repudiate a signature that originally appeared to be valid but was actually invalid.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
openssl openssl 0.9.8h |
||
openssl openssl 0.9.8i |
||
openssl openssl 0.9.8j |