CVE-2009-0127 describes a vulnerability in M2Crypto where it fails to properly check return values from OpenSSL verification functions, potentially allowing remote attackers to bypass certificate chain validation through malformed SSL/TLS signatures. This issue affects the heikkitoivonen m2crypto product. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), it represents a medium-severity vulnerability that could lead to information disclosure without requiring authentication or complex attack methods. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion, and a Linux vendor disputes its relevance to M2Crypto.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:heikkitoivonen:m2crypto:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.