PT-2008-1089 · Stunnel · Stunnel

Publicado

2008-05-23

·

Atualizado

2017-08-08

·

CVE-2008-2420

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions stunnel versions prior to 4.24
Description The issue concerns the stunnel package, where a flaw in the OCSP functionality allows remote attackers to bypass intended access restrictions by using revoked certificates, potentially leading to breaches in confidentiality, integrity, and availability of protected information. This can be exploited remotely.
Recommendations For versions prior to 4.24, update to version 4.24 or later to resolve the issue. As a temporary workaround, consider restricting access to the OCSP functionality until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09346
CVE-2008-2420

Produtos afetados

Stunnel