CVE Database
/

CVE-2015-1793

Back to search

CVE-2015-1793

Published: Jul 9, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.

VendorProductVersions

n/a

n/a

affected
n/a

References

SSRT102180
vendor-advisory
x_refsource_HP
1032817
vdb-entry
x_refsource_SECTRACK
GLSA-201507-15
vendor-advisory
x_refsource_GENTOO
FreeBSD-SA-15:12
vendor-advisory
x_refsource_FREEBSD
FEDORA-2015-11414
vendor-advisory
x_refsource_FEDORA
HPSBGN03424
vendor-advisory
x_refsource_HP
FEDORA-2015-11475
vendor-advisory
x_refsource_FEDORA
91787
vdb-entry
x_refsource_BID
HPSBUX03388
vendor-advisory
x_refsource_HP
75652
vdb-entry
x_refsource_BID
38640
exploit
x_refsource_EXPLOIT-DB
SSA:2015-190-01
vendor-advisory
x_refsource_SLACKWARE
NetBSD-SA2015-008
vendor-advisory
x_refsource_NETBSD

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now