|
|
| |
|
| |
bind: validation bypass
| Package(s): | Bind |
CVE #(s): | CVE-2009-0025
|
| Created: | January 9, 2009 |
Updated: | July 30, 2009 |
| Description: |
From the Red Hat advisory: A flaw was discovered in the way BIND checked the return value of the OpenSSL DSA_do_verify function. On systems using DNSSEC, a malicious zone could present a malformed DSA certificate and bypass proper certificate validation, allowing spoofing attacks. |
| Alerts: |
|
( Log in to post comments)
|
|
|