CVE-2009-0046: Medium severity Sun Grid Engine vulnerability
Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVPVerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0046?
CVE-2009-0046 is classified as having a high severity due to its potential for circumventing certificate chain validation.
How do I fix CVE-2009-0046?
To fix CVE-2009-0046, upgrade to a version of Sun Grid Engine that is later than 5.3.
What causes CVE-2009-0046?
CVE-2009-0046 is caused by improper validation of SSL/TLS signatures in Sun Grid Engine versions 5.3 and earlier.
Who is affected by CVE-2009-0046?
CVE-2009-0046 affects users running Sun Grid Engine versions up to and including 5.3.
Can CVE-2009-0046 be exploited remotely?
Yes, CVE-2009-0046 can be exploited remotely by attackers to bypass security checks.