Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4gvm-4mw2-9fpv

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

EPSS

Процентиль: 80%
0.01455
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 16 лет назад

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

redhat
больше 16 лет назад

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

nvd
больше 16 лет назад

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

debian
больше 16 лет назад

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check th ...

oracle-oval
почти 16 лет назад

ELSA-2009-1140: ruby security update (MODERATE)

EPSS

Процентиль: 80%
0.01455
Низкий

Дефекты

CWE-287