Title : ISC BIND "EVP_VerifyFinal()" Signature Spoofing Vulnerability VUPEN ID : VUPEN/ADV-2009-0043 CVE ID : CVE-2008-5077 - CVE-2009-0025 - CVE-2009-0265 CWE ID : CWE-347
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2009-01-08
Technical Description
A vulnerability has been identified in ISC BIND, which could be exploited by attackers to bypass security restrictions. This issue is caused due to various functions not properly checking the result of the "EVP_VerifyFinal()" and "DSA_do_verify()" functions when validating signatures, which could cause a malformed signature to be treated as valid, leading to spoofing attacks.