Back

Nortel Response to OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulnerability

nortel.com
03/03/2009 12:00 UTC+1000
AUSCERT External Security Bulletin Redistribution

This is member-only content.

Some features are reserved for our members. For full access, please login or become a member.

Details

CVSS (Max)
Not Available
Products
XXXXXXX
Publisher
Nortel
OS
Network Appliance Impact: Provide Misleading Information Access: Remote/Unauthenticated CVE Names: CVE-2008-5077 Ref: AA-2009.0029 ESB-2009.0009 ESB-2009.0017 ESB-2009.0020 ESB-2009.0038 ESB-2009.0110 Original Bulletin: http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=837653 - --------------------------BEGIN INCLUDED TEXT-------------------- Nortel Response to OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulnerability BULLETIN ID: 2009009350, Rev 1 PUBLISHED: 2009-02-26 STATUS: Active REGION: All PRIORITY: Critical TYPE: Security Advisory Source: 1. OpenSSL 07-Jan-2009 - http://www.openssl.org/news/secadv_20090107.txt 2. CVE-2008-5077 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077 3. Secunia SA33338 - http://secunia.com/advisories/33338/ Overview: A vulnerability has been reported in OpenSSL, which can be exploited by malicious people to conduct spoofing attacks. Some Nortel products contain this software as a component and thus are potentially affected. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. The vulnerability is caused due to certain OpenSSL functions not correctly verifying the return value of the "EVP_VerifyFinal()" function when validating the signature of DSA and ECDSA keys. This can be exploited to bypass the signature check, such as by sending a specially crafted signature of a certificate chain to a client. Successful exploitation requires that the server uses a certificate containing a DSA or ECDSA key. Please refer to the vendor link for additional information - http://www.openssl.org/news/secadv_20090107.txt This bulletin addresses the following CVE: - - CVE-2008-5077 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077) OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys. Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories Symptoms: Please refer to the links provided in the Source section for additional information about the vulnerabilities addressed and the vendor fix. Please refer to the Resolution section for Nortel-specific recommendations. Prevention: Please refer to the links provided in the Source section for additional information about the vulnerabilities addressed and the vendor fix. Please refer to the Resolution section for Nortel-specific recommendations. Mitigation: Please refer to the links provided in the Source section for additional information about the vulnerabilities addressed and the vendor fix. Please refer to the Resolution section for Nortel-specific recommendations. Risk: Please refer to the links provided in the Overview section for additional information about the vulnerabilities addressed and the vendor fix. Please refer to the Resolution section for Nortel-specific recommendations.
CVE(s)
XXXXXXXXXXXXX