Логотип exploitDog
bind: "CVE-2022-1343"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-1343"

Количество 10

Количество 10

ubuntu логотип

CVE-2022-1343

около 3 лет назад

The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successfu...

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-1343

около 3 лет назад

The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successfu...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-1343

около 3 лет назад

The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful r

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-1343

около 3 лет назад

The function `OCSP_basic_verify` verifies the signer certificate on an ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-mfm6-r9g2-q4r7

около 3 лет назад

`OCSP_basic_verify` may incorrectly verify the response signing certificate

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2022-03175

около 3 лет назад

Уязвимость реализации функции OCSP_basic_verify() библиотеки OpenSSL, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 4.8
EPSS: Низкий
oracle-oval логотип

ELSA-2022-9751

почти 3 года назад

ELSA-2022-9751: openssl security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-6224

почти 3 года назад

ELSA-2022-6224: openssl security and bug fix update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2306-1

почти 3 года назад

Security update for openssl-3

EPSS: Низкий
redos логотип

ROS-20220524-01

около 3 лет назад

Множественные уязвимости OpenSSL

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-1343

The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successfu...

CVSS3: 5.3
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-1343

The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successfu...

CVSS3: 5.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-1343

The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful r

CVSS3: 5.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-1343

The function `OCSP_basic_verify` verifies the signer certificate on an ...

CVSS3: 5.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-mfm6-r9g2-q4r7

`OCSP_basic_verify` may incorrectly verify the response signing certificate

CVSS3: 5.3
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-03175

Уязвимость реализации функции OCSP_basic_verify() библиотеки OpenSSL, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 4.8
0%
Низкий
около 3 лет назад
oracle-oval логотип
ELSA-2022-9751

ELSA-2022-9751: openssl security update (MODERATE)

почти 3 года назад
oracle-oval логотип
ELSA-2022-6224

ELSA-2022-6224: openssl security and bug fix update (MODERATE)

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2306-1

Security update for openssl-3

почти 3 года назад
redos логотип
ROS-20220524-01

Множественные уязвимости OpenSSL

около 3 лет назад

Уязвимостей на страницу