RUSTSEC-2022-0027

    Dashboard / Vulnerabilities / RUSTSEC-2022-0027

    RUSTSEC-2022-0027

    Published: 3 May 2022Last Modified: 8 Nov 2023

    Summary: `OCSP_basic_verify` may incorrectly verify the response signing certificate

    Details: The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0.

    Affected packages

    Package

    Name: openssl-src

    Purl: pkg:cargo/openssl-src

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 300.0.0
    Fixed -300.0.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2022-0027 | CVE-DB