OpenSSL Signature Verification Issue in Sun GridEngine from Sun Microsystems
CVE-2009-0046

Currently unrated

Key Information:

Vendor

Oracle

Vendor
CVE Published:
7 January 2009

What is CVE-2009-0046?

The vulnerability in Sun GridEngine affects versions 5.3 and earlier, where the software fails to validate the return value from the OpenSSL EVP_VerifyFinal function adequately. This flaw enables remote attackers to bypass the certificate chain validation process by exploiting a malformed SSL/TLS signature for DSA and ECDSA keys, which poses a significant risk to data integrity and authentication within the application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.