CVE-2009-0128

Publication date 15 January 2009

Last updated 24 July 2024


Ubuntu priority

plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

Status

Package Ubuntu Release Status
slurm-llnl 11.10 oneiric
Not affected
11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
9.04 jaunty
Not affected
8.10 intrepid
Fixed 1.3.6-1lenny3build0.8.10.1
8.04 LTS hardy Ignored end of life
7.10 gutsy Not in release
6.06 LTS dapper Not in release