CVE-2009-0128
SLURM - Certificate Validation Bypass
Title source: llmDescription
plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scores
EPSS
0.0008
EPSS Percentile
23.0%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
llnl/slurm
Timeline
Published
Jan 15, 2009
Tracked Since
Feb 18, 2026