5.3
CVSSv3

CVE-2017-8301

Published: 27/04/2017 Updated: 03/10/2019
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd libressl 2.5.2

openbsd libressl 2.5.3

openbsd libressl 2.5.1