Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gale | Gale | * | 0.99 (including) |
Gale | Gale | 0.15 (including) | 0.15 (including) |
Gale | Gale | 0.15b (including) | 0.15b (including) |
Gale | Gale | 0.15c (including) | 0.15c (including) |
Gale | Gale | 0.16 (including) | 0.16 (including) |
Gale | Gale | 0.16a (including) | 0.16a (including) |
Gale | Gale | 0.17 (including) | 0.17 (including) |
Gale | Gale | 0.17a (including) | 0.17a (including) |
Gale | Gale | 0.18 (including) | 0.18 (including) |
Gale | Gale | 0.18b (including) | 0.18b (including) |
Gale | Gale | 0.18c (including) | 0.18c (including) |
Gale | Gale | 0.19 (including) | 0.19 (including) |
Gale | Gale | 0.19a (including) | 0.19a (including) |
Gale | Gale | 0.19b (including) | 0.19b (including) |
Gale | Gale | 0.20a (including) | 0.20a (including) |
Gale | Gale | 0.21 (including) | 0.21 (including) |
Gale | Gale | 0.90a (including) | 0.90a (including) |
Gale | Gale | 0.90b (including) | 0.90b (including) |
Gale | Gale | 0.90c (including) | 0.90c (including) |
Gale | Gale | 0.91 (including) | 0.91 (including) |
Gale | Gale | 0.91a (including) | 0.91a (including) |
Gale | Gale | 0.91b (including) | 0.91b (including) |