Lucene search

K
suseSuseSUSE-SA:2009:006
HistoryJan 23, 2009 - 4:31 p.m.

SSL certificate checking bypass in openssl

2009-01-2316:31:52
lists.opensuse.org
24

EPSS

0.007

Percentile

81.0%

The OpenSSL certificate checking routines EVP_VerifyFinal can return negative values and 0 on failure. In some places negative values were not checked and considered successful verification. Prior to this update it was possible to bypass the certification chain checks of openssl.

Solution

There is no known workaround, please install the update packages.