Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 05:46:51 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=2111309266&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F0901-advisories%2FoCERT-2008-016.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.2111309266.1338184011.1338184011.1338184011.1%3B%2B__utmz%3D32867617.1338184011.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Open Source CERT Security Advisory 2008.16 http://packetstormsecurity.org/files/73658/oCERT-2008-016.txt http://packetstormsecurity.org/files/73658/oCERT-2008-016.txt http://packetstormsecurity.org/files/73658/Open-Source-CERT-Security-Advisory-2008.16.html Wed, 07 Jan 2009 20:17:20 GMT Several functions inside the OpenSSL library incorrectly check the result after calling the EVP_VerifyFinal function. This bug allows a malformed signature to be treated as a good signature rather than as an error. This issue affects the signature checks on DSA and ECDSA keys used with SSL/TLS. The flaw may be exploited by a malicious server or a man-in-the-middle attack that presents a malformed SSL/TLS signature from a certificate chain to a vulnerable client, bypassing validation.