CVE-2011-3207

crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.
References
Link Resource
http://cvs.openssl.org/chngview?cn=21349 Patch
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065712.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065744.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.html
http://marc.info/?l=bugtraq&m=133226187115472&w=2
http://marc.info/?l=bugtraq&m=133226187115472&w=2
http://openssl.org/news/secadv_20110906.txt Vendor Advisory
http://secunia.com/advisories/45956
http://secunia.com/advisories/57353
http://support.apple.com/kb/HT5784
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564
http://www.mandriva.com/security/advisories?name=MDVSA-2011:137
http://www.redhat.com/support/errata/RHSA-2011-1409.html
http://www.securitytracker.com/id?1026012
https://bugzilla.redhat.com/show_bug.cgi?id=736087
http://cvs.openssl.org/chngview?cn=21349 Patch
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065712.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065744.html
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.html
http://marc.info/?l=bugtraq&m=133226187115472&w=2
http://marc.info/?l=bugtraq&m=133226187115472&w=2
http://openssl.org/news/secadv_20110906.txt Vendor Advisory
http://secunia.com/advisories/45956
http://secunia.com/advisories/57353
http://support.apple.com/kb/HT5784
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564
http://www.mandriva.com/security/advisories?name=MDVSA-2011:137
http://www.redhat.com/support/errata/RHSA-2011-1409.html
http://www.securitytracker.com/id?1026012
https://bugzilla.redhat.com/show_bug.cgi?id=736087
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*

History

21 Nov 2024, 01:29

Type Values Removed Values Added
References () http://cvs.openssl.org/chngview?cn=21349 - Patch () http://cvs.openssl.org/chngview?cn=21349 - Patch
References () http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html - () http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065712.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065712.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065744.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065744.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.html - () http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092905.html -
References () http://marc.info/?l=bugtraq&m=133226187115472&w=2 - () http://marc.info/?l=bugtraq&m=133226187115472&w=2 -
References () http://openssl.org/news/secadv_20110906.txt - Vendor Advisory () http://openssl.org/news/secadv_20110906.txt - Vendor Advisory
References () http://secunia.com/advisories/45956 - () http://secunia.com/advisories/45956 -
References () http://secunia.com/advisories/57353 - () http://secunia.com/advisories/57353 -
References () http://support.apple.com/kb/HT5784 - () http://support.apple.com/kb/HT5784 -
References () http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564 - () http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004564 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2011:137 - () http://www.mandriva.com/security/advisories?name=MDVSA-2011:137 -
References () http://www.redhat.com/support/errata/RHSA-2011-1409.html - () http://www.redhat.com/support/errata/RHSA-2011-1409.html -
References () http://www.securitytracker.com/id?1026012 - () http://www.securitytracker.com/id?1026012 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=736087 - () https://bugzilla.redhat.com/show_bug.cgi?id=736087 -

Information

Published : 2011-09-22 10:55

Updated : 2024-11-21 01:29


NVD link : CVE-2011-3207

Mitre link : CVE-2011-3207

CVE.ORG link : CVE-2011-3207


JSON object : View

Products Affected

openssl

  • openssl
CWE
CWE-264

Permissions, Privileges, and Access Controls