Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-0049


Vulnerability Score 5.0 5.0
CVE Id CVE-2009-0049
Last Modified 30 Oct 2012 11:13:09
Published 07 Jan 2009 01:30:15
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE



Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

Vulnerable Systems


  • Eidlib 2.6.0



SECUNIA - 34029

SUSE - SUSE-SR:2009:005

BUGTRAQ - 20090107 [oCERT-2008-016] Multiple OpenSSL signature verification API misuses

Last Updated: 27 May 2016 10:49:48