CVE-2008-2420
N/A
N/A
Summary
The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass intended access restrictions by using revoked certificates.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://secunia.com/advisories/30425
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42528
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00942.html
- http://www.vupen.com/english/advisories/2008/1569/references
- http://secunia.com/advisories/30335
- http://secunia.com/advisories/31438
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00856.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:168
- http://stunnel.mirt.net/pipermail/stunnel-announce/2008-May/000035.html
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00907.html
- http://security.gentoo.org/glsa/glsa-200808-08.xml
- http://www.securityfocus.com/bid/29309
References
- http://secunia.com/advisories/30425
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42528
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00942.html
- http://www.vupen.com/english/advisories/2008/1569/references
- http://secunia.com/advisories/30335
- http://secunia.com/advisories/31438
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00856.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:168
- http://stunnel.mirt.net/pipermail/stunnel-announce/2008-May/000035.html
- https://www.redhat.com/archives/fedora-package-announce/2008-May/msg00907.html
- http://security.gentoo.org/glsa/glsa-200808-08.xml
- http://www.securityfocus.com/bid/29309
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.