Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gj3x-586x-w7gm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.

EPSS

Процентиль: 74%
0.00843
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 6 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.

CVSS3: 5.3
nvd
почти 6 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.

CVSS3: 5.3
debian
почти 6 лет назад

An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL ...

suse-cvrf
почти 6 лет назад

Security update for openfortivpn

EPSS

Процентиль: 74%
0.00843
Низкий