UBUNTU-CVE-2015-1793
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-1793
Summary:
Details: The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
References: https://ubuntu.com/security/CVE-2015-1793, https://mta.openssl.org/pipermail/openssl-announce/2015-July/000037.html, https://www.openssl.org/news/secadv_20150709.txt, https://www.cve.org/CVERecord?id=CVE-2015-1793
Affected packages
Package
Name: openssl
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
