5
CVSSv2

CVE-2011-3207

Published: 22/09/2011 Updated: 26/03/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

crypto/x509/x509_vfy.c in OpenSSL 1.0.x prior to 1.0.0e does not initialize certain structure members, which makes it easier for remote malicious users to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 1.0.0

openssl openssl 1.0.0b

openssl openssl 1.0.0d

openssl openssl 1.0.0a

openssl openssl 1.0.0c

Vendor Advisories

An uninitialized variable use flaw was found in OpenSSL This flaw could cause an application using the OpenSSL Certificate Revocation List (CRL) checking functionality to incorrectly accept a CRL that has a nextUpdate date in the past All OpenSSL users should upgrade to these updated packages, which contain a backported patch to resolve this issu ...