OpenSSL Alternative Certificate Chain Validation Vulnerability
RISK: High Risk
TYPE: Security software and application - Security Software & Appliance
A vulnerability was identified in OpenSSL. A remote user can bypass certificate validation on the target system.
When the validation of a certificate chain fails, the system attempts to validate an alternate certificate chain but does not check the CA flag of untrusted certificates. As a result, a remote user can cause the target system to validate an invalid certificate using a valid leaf certificate.
Impact
- Information Disclosure
- Spoofing
- Data Manipulation
System / Technologies affected
- Version 1.0.1o, 1.0.1n, 1.0.2b, 1.0.2c
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 1.0.1p or 1.0.2d
Vulnerability Identifier
Source
Related Link
Share with