Описание
PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.
Ссылки
- Issue TrackingPatch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.15.5 (включая) до 5.9.2 (исключая)
cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*
EPSS
Процентиль: 7%
0.00171
Низкий
7.5 High
CVSS3
Дефекты
CWE-347
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 1 месяца назад
PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.
msrc
около 1 месяца назад
PKCS7_verify signer confusion allows forged signatures to be accepted
CVSS3: 7.5
debian
около 1 месяца назад
PKCS7_verify signer confusion allows forged signatures, where the sign ...
CVSS3: 7.5
github
около 1 месяца назад
PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.
EPSS
Процентиль: 7%
0.00171
Низкий
7.5 High
CVSS3
Дефекты
CWE-347