Security Advisory

CVE-2014-8275

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-01-09 02:00:00
Last updated 2024-08-06 13:10:50
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.