>> Belgian eID middleware "EVP_VerifyFinal()" Spoofing Vulnerability
Title : Belgian eID middleware "EVP_VerifyFinal()" Spoofing Vulnerability VUPEN ID : VUPEN/ADV-2009-0048 CVE ID : CVE-2008-5077 - CVE-2009-0049 CWE ID : CWE-347
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2009-01-08
Technical Description
A vulnerability has been identified in Belgian eID middleware (eidlib), which could be exploited by attackers to bypass security restrictions. This issue is caused due to various functions not properly checking the result of the OpenSSL "EVP_VerifyFinal()" function when validating signatures, which could cause a malformed signature to be treated as valid, leading to spoofing attacks.