Gentoo Linux Security Advisory GLSA 200902-02 – An error in the OpenSSL certificate chain validation might allow for spoofing attacks. The Google Security Team reported that several functions incorrectly check the result after calling the EVP_VerifyFinal() function, allowing a malformed signature to be treated as a good signature rather than as an error. This issue affects the signature checks on DSA and ECDSA keys used with SSL/TLS. Versions less than 0.9.8j are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/74909/glsa-200902-02.txt
Source: https://packetstormsecurity.com/files/74909/Gentoo-Linux-Security-Advisory-200902-2.html

