Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
info
discussion
exploit
solution
references
Multiple Vendor OpenSSL 'DSA_verify' Function Signature Verification Vulnerability
References:
#2008-016 multiple OpenSSL signature verification API misuse
(oCERT)
008: SECURITY FIX: January 14, 2009
(OpenBSD)
008: SECURITY FIX: January 14, 2009
(OpenBSD)
BIND
(ISC)
BOINC Homepage
(University of California)
boinc-client: Does not check the RSA_public_decrypt() return value.
(Jan Lieskovsky)
boinc: Does not check the RSA_public_decrypt() return value.
(Kurt Roeckx)
Lasso
(Entrouvert)
libcrypt-openssl-dsa-perl: return values of openssl functions.
(Kurt Roeckx)
libnasl: OpenSSL incorrect checks for malformed signatures
(Jan Lieskovsky)
libnasl: Return values of DSA_do_verify
(Kurt Roeckx)
m2crypto: OpenSSL incorrect checks for malformed signatures
(Jan Lieskovsky)
m2crypto: openssl return values.
(Kurt Roeckx)
slurm-llnl: Imporer checking of EVP_VerifyFinal() return value.
(Kurt Roeckx)
ZXID Home Page
(ZXID)
250846 Security Vulnerability in Solaris BIND named(1M)
(Sun)
Avaya advisory ASA-2009-045
(Avaya)
BIND Security Vulnerability - EVP_VerifyFinal() and DSA_do_verify() return check
(ISC)
Privacy Statement
Copyright 2009, SecurityFocus