Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.112944
Category:General
Title:OpenSSL: Incorrect Error Checking During CMS Verification (20090325) - Windows
Summary:OpenSSL is prone to incorrect error checking during CMS verification.
Description:Summary:
OpenSSL is prone to incorrect error checking during CMS verification.

Vulnerability Insight:
The function CMS_verify() does not correctly handle an error
condition involving malformed signed attributes. This will cause an invalid set of signed
attributes to appear valid and content digests will not be checked.

Affected Software/OS:
OpenSSL 0.9.8h through 0.9.8j.

Solution:
Update to version 0.9.8k or later.

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0591
1021907
http://securitytracker.com/id?1021907
34256
http://www.securityfocus.com/bid/34256
34411
http://secunia.com/advisories/34411
34460
http://secunia.com/advisories/34460
34666
http://secunia.com/advisories/34666
35065
http://secunia.com/advisories/35065
35380
http://secunia.com/advisories/35380
35729
http://secunia.com/advisories/35729
36701
http://secunia.com/advisories/36701
42724
http://secunia.com/advisories/42724
42733
http://secunia.com/advisories/42733
52865
http://www.osvdb.org/52865
ADV-2009-0850
http://www.vupen.com/english/advisories/2009/0850
ADV-2009-1020
http://www.vupen.com/english/advisories/2009/1020
ADV-2009-1175
http://www.vupen.com/english/advisories/2009/1175
ADV-2009-1548
http://www.vupen.com/english/advisories/2009/1548
APPLE-SA-2009-09-10-2
http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html
HPSBOV02540
http://marc.info/?l=bugtraq&m=127678688104458&w=2
HPSBUX02435
http://marc.info/?l=bugtraq&m=124464882609472&w=2
NetBSD-SA2009-008
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc
SSRT090059
SUSE-SR:2009:010
http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html
http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847
http://support.apple.com/kb/HT3865
http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html
http://www.openssl.org/news/secadv_20090325.txt
http://www.php.net/archive/2009.php#id2009-04-08-1
https://kb.bluecoat.com/index?page=content&id=SA50
openssl-cmsverify-security-bypass(49432)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49432
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.