Title : NTP OpenSSL "EVP_VerifyFinal()" Signature Spoofing Vulnerability VUPEN ID : VUPEN/ADV-2009-0042 CVE ID : CVE-2008-5077 - CVE-2009-0021 CWE ID : CWE-347
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2009-01-08
Technical Description
A vulnerability has been identified in NTP, which could be exploited by attackers to bypass security restrictions. This issue is caused due to various functions not properly checking the result of the OpenSSL "EVP_VerifyFinal()" function when validating signatures, which could cause a malformed signature to be treated as valid, leading to spoofing and phishing attacks.