DEBIAN-CVE-2009-0127

Source
https://security-tracker.debian.org/tracker/CVE-2009-0127
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0127.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2009-0127
Upstream
Published
2009-01-15T17:30:00.577Z
Modified
2026-03-07T17:01:36.449533Z
Summary
[none]
Details

M2Crypto does not properly check the return value from the OpenSSL EVPVerifyFinal, DSAverify, ECDSAverify, DSAdoverify, and ECDSAdo_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto.

References

Affected packages

Debian:11 / m2crypto

Package

Name
m2crypto
Purl
pkg:deb/debian/m2crypto?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.37.1-2
0.38.0-1
0.38.0-2
0.38.0-3
0.38.0-4
0.38.0-4.1
0.40.1-1
0.40.1-2
0.40.1-3
0.40.1-4
0.41.0-1
0.41.0+ds-1
0.41.0+ds-2
0.41.0+ds-3
0.42.0-1
0.42.0-2
0.42.0-2.1
0.42.0-3
0.46.2-1
0.46.2-2
0.46.2-3

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0127.json"

Debian:12 / m2crypto

Package

Name
m2crypto
Purl
pkg:deb/debian/m2crypto?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.38.0-4
0.38.0-4.1
0.40.1-1
0.40.1-2
0.40.1-3
0.40.1-4
0.41.0-1
0.41.0+ds-1
0.41.0+ds-2
0.41.0+ds-3
0.42.0-1
0.42.0-2
0.42.0-2.1
0.42.0-3
0.46.2-1
0.46.2-2
0.46.2-3

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0127.json"

Debian:13 / m2crypto

Package

Name
m2crypto
Purl
pkg:deb/debian/m2crypto?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.42.0-3
0.46.2-1
0.46.2-2
0.46.2-3

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0127.json"