lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-21T15:17:51.443Z
Reserved: 2009-01-15T00:00:00Z
Link: CVE-2009-0130
Updated: 2024-08-07T04:24:17.532Z
Status : Deferred
Published: 2009-01-15T17:30:00.640
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-0130
No data.
OpenCVE Enrichment
No data.
Weaknesses