SecBoard
Zurück zur CVE-Übersicht

CVE-2017-8301

LOW(2.6)

AV:N/AC:H/Au:N/C:N/I:P/A:N

Risk Signal Score7/100 — NIEDRIG

EPSS-Score

1%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

2.6

Technische Schwere

Beschreibung

LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.

Referenzen