Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-3207

Опубликовано: 22 сент. 2011
Источник: debian
EPSS Низкий

Описание

crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensslfixed1.0.0e-1package
opensslnot-affectedsqueezepackage
opensslnot-affectedlennypackage

EPSS

Процентиль: 85%
0.02474
Низкий

Связанные уязвимости

ubuntu
почти 14 лет назад

crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.

redhat
почти 14 лет назад

crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.

nvd
почти 14 лет назад

crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.

github
около 3 лет назад

crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.

oracle-oval
почти 14 лет назад

ELSA-2011-1409: openssl security update (MODERATE)

EPSS

Процентиль: 85%
0.02474
Низкий