7.5
CVSSv2

CVE-2004-0004

Published: 17/02/2004 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and previous versions only compares the serial of the signer's certificate and the one in the database, which can cause OpenCA to incorrectly accept a signature if the certificate's chain is trusted by OpenCA's chain directory, allowing remote malicious users to spoof requests from other users.

Vulnerable Product Search on Vulmon Subscribe to Product

openca openca