DISPUTED lib/crypto/csrc/cryptodrv.c in erlang does not properly check the return value from the OpenSSL DSAdoverify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of cryptodrv.c, and thus "this report is invalid."
End of life: 5/26/2026, End of support: 5/17/2024, Latest version: 26.2.5.21
End of life: 5/26/2026, End of support: 5/17/2024, Latest version: 26.2.5.21
End of life: 3/18/2024, End of support: 5/11/2020, Latest version: 22.3.4.27
End of life: 3/18/2024, End of support: 5/11/2020, Latest version: 22.3.4.27
End of life: 3/14/2024, End of support: 5/10/2021, Latest version: 23.3.4.20
End of life: 3/14/2024, End of support: 5/10/2021, Latest version: 23.3.4.20
End of life: 5/20/2027, End of support: 5/20/2025, Latest version: 27.3.4.17
End of life: 5/20/2027, End of support: 5/20/2025, Latest version: 27.3.4.17
End of life: 5/20/2028, End of support: 5/11/2026, Latest version: 28.5.0.6
End of life: 5/11/2029, Latest version: 29.0.6