Back
Nortel Response to OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulnerability
nortel.com
03/03/2009 12:00 UTC+1000
AUSCERT External Security Bulletin Redistribution
This is member-only content.
Some features are reserved for our members. For full access, please login or become a member.
Details
CVSS (Max)
Not Available
Products
XXXXXXX
Publisher
Nortel
OS
Network Appliance
Impact: Provide Misleading Information
Access: Remote/Unauthenticated
CVE Names: CVE-2008-5077
Ref: AA-2009.0029
ESB-2009.0009
ESB-2009.0017
ESB-2009.0020
ESB-2009.0038
ESB-2009.0110
Original Bulletin:
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=837653
- --------------------------BEGIN INCLUDED TEXT--------------------
Nortel Response to OpenSSL 'EVP_VerifyFinal' Function Signature Verification
Vulnerability
BULLETIN ID: 2009009350, Rev 1
PUBLISHED: 2009-02-26
STATUS: Active
REGION: All
PRIORITY: Critical
TYPE: Security Advisory
Source:
1. OpenSSL 07-Jan-2009 -
http://www.openssl.org/news/secadv_20090107.txt
2. CVE-2008-5077 -
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077
3. Secunia SA33338 - http://secunia.com/advisories/33338/
Overview:
A vulnerability has been reported in OpenSSL, which can be exploited by
malicious people to conduct spoofing attacks. Some Nortel products contain
this software as a component and thus are potentially affected. This bulletin
provides a multi-product consolidated response for the Nortel products which
are potentially affected.
The vulnerability is caused due to certain OpenSSL functions not correctly
verifying the return value of the "EVP_VerifyFinal()" function when validating
the signature of DSA and ECDSA keys. This can be exploited to bypass the
signature check, such as by sending a specially crafted signature of a
certificate chain to a client. Successful exploitation requires that the
server uses a certificate containing a DSA or ECDSA key.
Please refer to the vendor link for additional information -
http://www.openssl.org/news/secadv_20090107.txt
This bulletin addresses the following CVE:
- - CVE-2008-5077 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077)
OpenSSL 0.9.8i and earlier does not properly check the return value from the
EVP_VerifyFinal function, which allows remote attackers to bypass validation
of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA
keys.
Before taking any action please ensure that you are viewing the latest
official version of this security advisory by referencing
http://www.nortel.com/securityadvisories
Symptoms:
Please refer to the links provided in the Source section for additional
information about the vulnerabilities addressed and the vendor fix. Please
refer to the Resolution section for Nortel-specific recommendations.
Prevention:
Please refer to the links provided in the Source section for additional
information about the vulnerabilities addressed and the vendor fix. Please
refer to the Resolution section for Nortel-specific recommendations.
Mitigation:
Please refer to the links provided in the Source section for additional
information about the vulnerabilities addressed and the vendor fix. Please
refer to the Resolution section for Nortel-specific recommendations.
Risk:
Please refer to the links provided in the Overview section for additional
information about the vulnerabilities addressed and the vendor fix. Please
refer to the Resolution section for Nortel-specific recommendations.
CVE(s)
XXXXXXXXXXXXX