Novell Home

CVE-2009-0591

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

CVE-2009-0591 at MITRE

Details

The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.
Novell Bugzilla entry: 489641

SUSE Security Advisories:

Product(s) Fixed package version(s) References
openSUSE 11.1
  • openssl-debuginfo >= 0.9.8h-28.8.1
  • openssl-debugsource >= 0.9.8h-28.8.1
SAT Patch Nr: 786
openSUSE 11.1
  • libopenssl-devel >= 0.9.8h-28.8.1
  • libopenssl0_9_8 >= 0.9.8h-28.8.1
  • libopenssl0_9_8-32bit >= 0.9.8h-28.8.1
  • libopenssl0_9_8-64bit >= 0.9.8h-28.8.1
  • openssl >= 0.9.8h-28.8.1
  • openssl-doc >= 0.9.8h-28.8.1
SAT Patch Nr: 786
SLES 11 DEBUGINFO
  • openssl-debuginfo >= 0.9.8h-30.12.1
  • openssl-debugsource >= 0.9.8h-30.12.1
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. ia64
SAT Patch Nr: 772
SLE 11
  • libopenssl-devel >= 0.9.8h-30.12.1
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. ia64
SAT Patch Nr: 772
SLED 11
  • libopenssl0_9_8 >= 0.9.8h-30.12.1
  • openssl >= 0.9.8h-30.12.1
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. ia64
SAT Patch Nr: 772
SLED 11
  • libopenssl0_9_8 >= 0.9.8h-30.12.1
  • libopenssl0_9_8-32bit >= 0.9.8h-30.12.1
  • openssl >= 0.9.8h-30.12.1
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. ia64
SAT Patch Nr: 772
SLES 11
  • libopenssl0_9_8 >= 0.9.8h-30.12.1
  • openssl >= 0.9.8h-30.12.1
  • openssl-doc >= 0.9.8h-30.12.1
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. ia64
SAT Patch Nr: 772
SLES 11
  • libopenssl0_9_8 >= 0.9.8h-30.12.1
  • libopenssl0_9_8-x86 >= 0.9.8h-30.12.1
  • openssl >= 0.9.8h-30.12.1
  • openssl-doc >= 0.9.8h-30.12.1
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. ia64
SAT Patch Nr: 772
SLES 11
  • libopenssl0_9_8 >= 0.9.8h-30.12.1
  • libopenssl0_9_8-32bit >= 0.9.8h-30.12.1
  • openssl >= 0.9.8h-30.12.1
  • openssl-doc >= 0.9.8h-30.12.1
sle11-debuginfo. s390x
sle11-debuginfo. x86-64
sle11-debuginfo. ppc
sle11-debuginfo. ppc
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. ia64
sle11-debuginfo. ia64
sle11-debuginfo. x86
sle11-debuginfo. s390x
sle11-debuginfo. x86
sle11-debuginfo. x86-64
sle11-debuginfo. x86-64
sle11-debuginfo. x86
sle11-debuginfo. ppc
sle11-debuginfo. x86-64
sle11-debuginfo. ia64
SAT Patch Nr: 772

Novell® Making IT Work As One

© 2009 Novell, Inc. All Rights Reserved.