CVE-2009-0129
libcrypt-openssl-dsa-perl - Info Disclosure
Title source: llmDescription
libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scores
EPSS
0.0008
EPSS Percentile
22.4%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
perl-openssl/libcrypt-openssl-dsa-perl
Timeline
Published
Jan 15, 2009
Tracked Since
Feb 18, 2026