OpenSSL Signature Verification Issue in Sun GridEngine from Sun Microsystems
CVE-2009-0046
Currently unrated
Summary
The vulnerability in Sun GridEngine affects versions 5.3 and earlier, where the software fails to validate the return value from the OpenSSL EVP_VerifyFinal function adequately. This flaw enables remote attackers to bypass the certificate chain validation process by exploiting a malformed SSL/TLS signature for DSA and ECDSA keys, which poses a significant risk to data integrity and authentication within the application.
References
Timeline
Vulnerability published
Vulnerability Reserved