CVE-2009-0049

NameCVE-2009-0049
DescriptionBelgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1946-1
NVD severitymedium (attack range: remote)
Debian Bugs511261

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
belpicsource(unstable)2.6.0-6medium511261
belpicsourceetch2.5.9-7.etch.1mediumDSA-1946-1

Search for package or bug name: Reporting problems