"value":"The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077."
},
{
"lang":"es",
"value":"La funci\u00f3n decrypt_public en lib/crypt.cpp en el cliente Berkeley Open Infrastructure for Network Computing (BOINC) v6.2.14 y v6.4.5, no comprueba adecuadamente el valor de retorno de la funci\u00f3n OpenSSL RSA_public_decrypt, lo que permitir\u00eda a atacantes remotos evitar la validaci\u00f3n en cadena de los certificados a trav\u00e9s de una firma SSL/TLS malformada, una vulnerabilidad similar a CVE-2008-5077."