Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-2903

Опубликовано: 06 окт. 2017
Источник: debian

Описание

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cyasslremovedpackage
wolfsslfixed3.4.8+dfsg-1package

Примечания

  • wolfssl actually fixed with the initial upload to unstable after the rename

  • according to maintainer addressed in 3.2.0 upstream

Связанные уязвимости

CVSS3: 5.9
nvd
больше 8 лет назад

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.

CVSS3: 5.9
github
больше 3 лет назад

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.