CVE-2009-0126
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
La función decrypt_public en lib/crypt.cpp en el cliente Berkeley Open Infrastructure for Network Computing (BOINC) v6.2.14 y v6.4.5, no comprueba adecuadamente el valor de retorno de la función OpenSSL RSA_public_decrypt, lo que permitiría a atacantes remotos evitar la validación en cadena de los certificados a través de una firma SSL/TLS malformada, una vulnerabilidad similar a CVE-2008-5077.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-01-15 CVE Reserved
- 2009-01-15 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://boinc.berkeley.edu/trac/changeset/16883 | X_refsource_confirm | |
http://openwall.com/lists/oss-security/2009/01/12/4 | Mailing List | |
http://secunia.com/advisories/33806 | Third Party Advisory | |
http://secunia.com/advisories/33828 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=511521 | 2024-08-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=479664 | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Berkeley Search vendor "Berkeley" | Boinc Client Search vendor "Berkeley" for product "Boinc Client" | 6.2.14 Search vendor "Berkeley" for product "Boinc Client" and version "6.2.14" | - |
Affected
| ||||||
Berkeley Search vendor "Berkeley" | Boinc Client Search vendor "Berkeley" for product "Boinc Client" | 6.4.5 Search vendor "Berkeley" for product "Boinc Client" and version "6.4.5" | - |
Affected
|