Total vulnerabilities in the database
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
Software | From | Fixed in |
---|---|---|
oracle / supply_chain_products_suite | 6.1.2.2 | 6.1.2.2.x |
oracle / supply_chain_products_suite | 6.2.0 | 6.2.0.x |
oracle / supply_chain_products_suite | 6.1.3.0 | 6.1.3.0.x |
oracle / jd_edwards_enterpriseone_tools | 9.2 | 9.2.x |
oracle / jd_edwards_enterpriseone_tools | 9.1 | 9.1.x |
openssl / openssl | 1.0.2b | 1.0.2b.x |
openssl / openssl | 1.0.2c | 1.0.2c.x |
openssl / openssl | 1.0.1n | 1.0.1n.x |
openssl / openssl | 1.0.1o | 1.0.1o.x |
oracle / opus_10g_ethernet_switch_family | - | 2.0.0.6.x |