Количество 23
Количество 23
BDU:2023-03312
Уязвимость криптографической библиотеки OpenSSL, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю обойти проверку политик для сертификата
ROS-20230619-04
Уязвимость OpenSSL
ALT-PU-2023-1876
ALT-PU-2023-1876: package `openssl1.1` update to version 1.1.1t-alt3
ALT-PU-2023-1804
ALT-PU-2023-1804: package `openssl1.1` update to version 1.1.1t-alt2
CVE-2023-0465
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
CVE-2023-0465
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
CVE-2023-0465
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
CVE-2023-0465
Invalid certificate policies in leaf certificates are silently ignored
CVE-2023-0465
Applications that use a non-default option when verifying certificates ...
SUSE-SU-2023:1960-1
Security update for openssl
SUSE-SU-2023:1912-1
Security update for compat-openssl098
GHSA-77f3-6546-6rj7
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.
SUSE-SU-2023:1926-1
Security update for openssl1
SUSE-SU-2023:1922-1
Security update for openssl-1_0_0
SUSE-SU-2023:1914-1
Security update for openssl-1_0_0
SUSE-SU-2023:1911-1
Security update for openssl-1_1
SUSE-SU-2023:1908-1
Security update for openssl-1_1
SUSE-SU-2023:1907-1
Security update for openssl
SUSE-SU-2023:1898-1
Security update for openssl-3
SUSE-SU-2023:1794-1
Security update for openssl-1_1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2023-03312 Уязвимость криптографической библиотеки OpenSSL, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю обойти проверку политик для сертификата | CVSS3: 5.3 | 2% Низкий | больше 3 лет назад | |
ROS-20230619-04 Уязвимость OpenSSL | CVSS3: 5.3 | 2% Низкий | больше 3 лет назад | |
ALT-PU-2023-1876 ALT-PU-2023-1876: package `openssl1.1` update to version 1.1.1t-alt3 | CVSS3: 7.5 | больше 3 лет назад | ||
ALT-PU-2023-1804 ALT-PU-2023-1804: package `openssl1.1` update to version 1.1.1t-alt2 | CVSS3: 7.5 | больше 3 лет назад | ||
CVE-2023-0465 Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. | CVSS3: 5.3 | 2% Низкий | больше 3 лет назад | |
CVE-2023-0465 Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. | CVSS3: 5.3 | 2% Низкий | больше 3 лет назад | |
CVE-2023-0465 Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. | CVSS3: 5.3 | 2% Низкий | больше 3 лет назад | |
CVE-2023-0465 Invalid certificate policies in leaf certificates are silently ignored | CVSS3: 5.3 | 2% Низкий | около 1 месяца назад | |
CVE-2023-0465 Applications that use a non-default option when verifying certificates ... | CVSS3: 5.3 | 2% Низкий | больше 3 лет назад | |
SUSE-SU-2023:1960-1 Security update for openssl | 2% Низкий | больше 3 лет назад | ||
SUSE-SU-2023:1912-1 Security update for compat-openssl098 | 2% Низкий | больше 3 лет назад | ||
GHSA-77f3-6546-6rj7 Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function. | CVSS3: 5.3 | 2% Низкий | больше 3 лет назад | |
SUSE-SU-2023:1926-1 Security update for openssl1 | больше 3 лет назад | |||
SUSE-SU-2023:1922-1 Security update for openssl-1_0_0 | больше 3 лет назад | |||
SUSE-SU-2023:1914-1 Security update for openssl-1_0_0 | больше 3 лет назад | |||
SUSE-SU-2023:1911-1 Security update for openssl-1_1 | больше 3 лет назад | |||
SUSE-SU-2023:1908-1 Security update for openssl-1_1 | больше 3 лет назад | |||
SUSE-SU-2023:1907-1 Security update for openssl | больше 3 лет назад | |||
SUSE-SU-2023:1898-1 Security update for openssl-3 | больше 3 лет назад | |||
SUSE-SU-2023:1794-1 Security update for openssl-1_1 | больше 3 лет назад |
Уязвимостей на страницу