OpenSSL Signature Verification Issue in Sun GridEngine from Sun Microsystems
CVE-2009-0046

Currently unrated

Key Information:

Vendor
Oracle
Vendor
CVE Published:
7 January 2009

Summary

The vulnerability in Sun GridEngine affects versions 5.3 and earlier, where the software fails to validate the return value from the OpenSSL EVP_VerifyFinal function adequately. This flaw enables remote attackers to bypass the certificate chain validation process by exploiting a malformed SSL/TLS signature for DSA and ECDSA keys, which poses a significant risk to data integrity and authentication within the application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.