Описание
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | released  | 1.8.4-1ubuntu1.7 | 
| devel | not-affected  | 1.8.7.174-1 | 
| gutsy | ignored  | end of life, was needed | 
| hardy | released  | 1.8.6.111-2ubuntu1.3 | 
| intrepid | released  | 1.8.7.72-1ubuntu0.2 | 
| jaunty | released  | 1.8.7.72-3ubuntu0.1 | 
| karmic | not-affected  | 1.8.7.174-1 | 
| lucid | not-affected  | 1.8.7.174-1 | 
| maverick | not-affected  | 1.8.7.174-1 | 
| natty | not-affected  | 1.8.7.174-1 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | ignored  | end of life | 
| devel | DNE  | pulled 2010-07-27 | 
| gutsy | ignored  | end of life, was needed | 
| hardy | ignored  | end of life | 
| intrepid | released  | 1.9.0.2-7ubuntu1.2 | 
| jaunty | released  | 1.9.0.2-9ubuntu1.1 | 
| karmic | not-affected  | 1.9.0.2-9.1ubuntu1 | 
| lucid | not-affected  | 1.9.0.2-9.1ubuntu1 | 
| maverick | DNE  | pulled 2010-07-27 | 
| natty | DNE  | pulled 2010-07-27 | 
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check th ...
ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.
EPSS
6.8 Medium
CVSS2