Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-0642

Опубликовано: 20 фев. 2009
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.8

Описание

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

РелизСтатусПримечание
dapper

released

1.8.4-1ubuntu1.7
devel

not-affected

1.8.7.174-1
gutsy

ignored

end of life, was needed
hardy

released

1.8.6.111-2ubuntu1.3
intrepid

released

1.8.7.72-1ubuntu0.2
jaunty

released

1.8.7.72-3ubuntu0.1
karmic

not-affected

1.8.7.174-1
lucid

not-affected

1.8.7.174-1
maverick

not-affected

1.8.7.174-1
natty

not-affected

1.8.7.174-1

Показывать по

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

pulled 2010-07-27
gutsy

ignored

end of life, was needed
hardy

ignored

end of life
intrepid

released

1.9.0.2-7ubuntu1.2
jaunty

released

1.9.0.2-9ubuntu1.1
karmic

not-affected

1.9.0.2-9.1ubuntu1
lucid

not-affected

1.9.0.2-9.1ubuntu1
maverick

DNE

pulled 2010-07-27
natty

DNE

pulled 2010-07-27

Показывать по

EPSS

Процентиль: 80%
0.01455
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

nvd
больше 16 лет назад

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

debian
больше 16 лет назад

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check th ...

github
около 3 лет назад

ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

oracle-oval
почти 16 лет назад

ELSA-2009-1140: ruby security update (MODERATE)

EPSS

Процентиль: 80%
0.01455
Низкий

6.8 Medium

CVSS2