« Volver al listado

CVE-2009-0591

Estado: ModificadaBaja (2.6)—

The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-0591",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-03-27T16:30:01.920",
  "references": [
    {
      "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=124464882609472&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=127678688104458&w=2",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/34411",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/34460",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/34666",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35065",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35380",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/35729",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/36701",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/42724",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/42733",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://securitytracker.com/id?1021907",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://support.apple.com/kb/HT3865",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openssl.org/news/secadv_20090325.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.osvdb.org/52865",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.php.net/archive/2009.php#id2009-04-08-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/34256",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0850",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1020",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1175",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1548",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49432",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://kb.bluecoat.com/index?page=content&id=SA50",
      "source": "secalert@redhat.com"
    },
    {
      "url": "ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2009/Sep/msg00004.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2009-05/msg00000.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=124464882609472&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=127678688104458&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34411",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34460",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34666",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35065",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35380",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/35729",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/36701",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42724",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42733",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1021907",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=671059&group_id=116847",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT3865",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://voodoo-circle.sourceforge.net/sa/sa-20090326-01.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openssl.org/news/secadv_20090325.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/52865",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.php.net/archive/2009.php#id2009-04-08-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34256",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0850",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1020",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1175",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1548",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49432",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://kb.bluecoat.com/index?page=content&id=SA50",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid."
    },
    {
      "lang": "es",
      "value": "La función CMS_verify en OpenSSL v0.9.8h hasta v0.9.8j, cuando se ha habilitado CMS, no maneja adecuadamente los errores asociados con atributos firmados malformados, permitiendo a atacantes remotos rechazar una firma que originalmente aparentaba ser válida pero que realmente será inválida."
    }
  ],
  "lastModified": "2026-06-16T23:05:22.593",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "261EE631-AB43-44FE-B02A-DFAAB8D35927"
            },
            {
              "criteria": "cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA0E0BBF-D0BE-41A7-B9BB-C28F01000BC0"
            },
            {
              "criteria": "cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A1365ED-4651-4AB2-A64B-43782EA2F0E8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Not vulnerable. This issue affected OpenSSL CMS functionality which is not present in the openssl packages as shipped with Red Hat Enterprise Linux 2.1, 3, 4 or 5.",
      "lastModified": "2009-03-30T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}