7.4
CVSSv3

CVE-2018-8970

Published: 24/03/2018 Updated: 24/04/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 prior to 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle malicious users to spoof servers and obtain sensitive information via a crafted certificate. NOTE: the LibreSSL documentation indicates that this special case is supported, but the BoringSSL documentation does not.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd libressl 2.7.0

Github Repositories

Demo for https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8970

Demo for CVE-2018-8970 cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2018-8970