Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23726
HistoryApr 10, 2020 - 12:34 a.m.

DSA Certificate Validation Bypass

2020-04-1000:34:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.019 Low

EPSS

Percentile

88.4%

bind is vulnerable to DSA certificate validation bypass. The vulnerability exists as a flaw was discovered in the way BIND checked the return value of the OpenSSL DSA_do_verify function. On systems using DNSSEC, a malicious zone could present a malformed DSA certificate and bypass proper certificate validation, allowing spoofing attacks.

References