CVE Vulnerabilities

CVE-2009-0051

Improper Authentication

Published: Jan 07, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
ZxidZxid*0.29 (including)
ZxidZxid0.1 (including)0.1 (including)
ZxidZxid0.2 (including)0.2 (including)
ZxidZxid0.3 (including)0.3 (including)
ZxidZxid0.4 (including)0.4 (including)
ZxidZxid0.5 (including)0.5 (including)
ZxidZxid0.6 (including)0.6 (including)
ZxidZxid0.7 (including)0.7 (including)
ZxidZxid0.8 (including)0.8 (including)
ZxidZxid0.9 (including)0.9 (including)
ZxidZxid0.10 (including)0.10 (including)
ZxidZxid0.11 (including)0.11 (including)
ZxidZxid0.12 (including)0.12 (including)
ZxidZxid0.13 (including)0.13 (including)
ZxidZxid0.14 (including)0.14 (including)
ZxidZxid0.15 (including)0.15 (including)
ZxidZxid0.16 (including)0.16 (including)
ZxidZxid0.17 (including)0.17 (including)
ZxidZxid0.18 (including)0.18 (including)
ZxidZxid0.19 (including)0.19 (including)
ZxidZxid0.20 (including)0.20 (including)
ZxidZxid0.21 (including)0.21 (including)
ZxidZxid0.22 (including)0.22 (including)
ZxidZxid0.25 (including)0.25 (including)
ZxidZxid0.26 (including)0.26 (including)
ZxidZxid0.27 (including)0.27 (including)
ZxidZxid0.28 (including)0.28 (including)

Potential Mitigations

References